MisusePrivilege AbuseData ExfiltratedEmployee Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
Montefiore Health System/University Hospital for Albert Einstein College of Medicine
bd_c34c6d1de9326442 · schema v1 · pii pii-v1
Full breach record for Montefiore Health System/University Hospital for Albert Einstein College of Medicine →Montefiore Health System reported a breach involving an employee who stole patient account information from the electronic medical record system between January 2013 and June 2013. Stolen data included names, addresses, SSNs, next of kin, and health insurance info. The employee was arrested and prosecuted. Montefiore provided 12 months of credit monitoring and identity theft protection via ID Experts to affected individuals.
California clockDiscovered May 15, 2015 → Notified Jun 17, 201533d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e46657d08ec969bbSouth Carolina State AGfiled 2015-06-22(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56456
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2015
- Raw hash
- cd631ba97fc3685cd488f772d52b532ade33fb7631539f828dfa997823f19ec7
Reporting entity
- Name
- Montefiore Health System/University Hospital for Albert Einstein College of Medicinenorm: montefiore health system university hospital for albert einstein college of medicine
Victim entity
- Name
- Montefiore Health System/University Hospital for Albert Einstein College of Medicinenorm: montefiore health system university hospital for albert einstein college of medicine
Incident
- Discovered
- May 15, 2015
- Materiality determined
- —
- Notification sent
- Jun 17, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Regulator citations
- cooperating with the police and the Manhattan District Attorney’s office
- Initial access
- insider_action
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 33d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 15, 2015→ Notified: Jun 17, 201533d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.