HackingVulnerability ExploitSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedData ExfiltratedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Sharp Health Plan
bd_baca2ffb3c1e65ac · schema v1 · pii pii-v1
Full breach record for Sharp Health Plan →Sharp Health Plan notified California residents that their PHI was accessed via a vulnerability in MOVEit Transfer software used by business associate Delta Dental. The unauthorized access occurred between May 27 and May 30, 2023. Affected data included names, SSNs, and dental treatment info. Delta Dental engaged forensics and notified law enforcement.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b38143b345712444California State AGfiled 2024-01-08Verified
- bd_c20ba0bba2832f31HHS OCRfiled 2024-01-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579056
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 8, 2024
- Raw hash
- 18a637e841f354445c28c8808dafe4ade42df2a21658546215baea320688a3cb
Reporting entity
- Name
- Sharp Health Plannorm: sharp health plan
Victim entity
- Name
- Sharp Health Plannorm: sharp health plan
Incident
- Discovered
- Nov 17, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Delta Dental
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.