AccidentalMisdeliveryData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedSupply Chain (3P Vendor)PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumResolved
Providence Saint Joseph Medical Center
bd_c4817e5e4c0e49c3 · schema v1 · pii pii-v1
Full breach record for Providence Saint Joseph Medical Center →Providence Saint Joseph Medical Center experienced a data breach on November 1, 2014, discovered on February 18, 2015. A staff member inadvertently sent patient medical billing information, including SSNs and demographic data, to a third-party billing vendor. The incident involved approximately 1,000+ individuals (based on attached notices). The organization engaged ID Experts for recovery, corrected billing, and refunded payments. No malicious intent was found; it was an internal clerical error.
California clockDiscovered Feb 18, 2015 → Notified Mar 10, 201520d ✓ CA 60-day OK21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-48785
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2015
- Raw hash
- 1ea213cce681507b62842eded9067dd8f3bd51c5e7b82b46daf5ff940de55b9c
Reporting entity
- Name
- Providence Saint Joseph Medical Centernorm: providence saint joseph medical center
Victim entity
- Name
- Providence Saint Joseph Medical Centernorm: providence saint joseph medical center
Incident
- Discovered
- Feb 18, 2015
- Materiality determined
- —
- Notification sent
- Mar 10, 2015
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1535 Unauthorized Access to Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- insider_action
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 18, 2015→ Notified: Mar 10, 201520d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.