HackingEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIMediumContained
Prospect Medical Holdings, Inc.
bd_bd24866d0fea52f9 · schema v1 · pii pii-v1
Full breach record for Prospect Medical Holdings, Inc. →Prospect Medical Holdings, Inc. notified California residents of a data breach where an unauthorized party accessed IT network files between July 31 and August 3, 2023. The company discovered the incident on August 1, 2023. Affected data included names and Social Security numbers of employees, dependents, and patients. The company engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring and identity protection services.
California clockDiscovered Aug 1, 2023 → Notified Sep 29, 202359d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_ff39eb1c7fdf07a1Leak Siterhysidafiled 2023-08-24(36d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_2fef4c679272ccd3HHS OCRfiled 2023-09-29Verified
- bd_35efeda2e5a8d88fNew Hampshire State AGfiled 2023-09-29Verified
- bd_6ef44d457fd8b260Maine State AGfiled 2023-09-29Verified
- bd_91573382e8c02419Vermont State AGfiled 2023-09-29Verified
Show 1 more filing ↓Show fewer ↑
- bd_f1bc0b4d5ad05a50Montana State AGfiled 2023-09-29Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574490
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2023
- Raw hash
- d878277bcedf1d8f7607be1f325827571a76fdd6b59f75f3f0a1360648362aa7
Reporting entity
- Name
- Prospect Medical Holdings, Inc.norm: prospect medical
- Domain
- pmh.com
Victim entity
- Name
- Prospect Medical Holdings, Inc.norm: prospect medical
- Domain
- pmh.com
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- Sep 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2023→ Notified: Sep 29, 202359d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.