MisusePrivilege AbuseEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Grimaldi Center for Wellness and Aesthetics
bd_c55233b7160bf183 · schema v1 · pii pii-v1
Full breach record for Grimaldi Center for Wellness and Aesthetics →Grimaldi Center for Wellness and Aesthetics, a healthcare provider in Chula Vista, CA, notified patients of a data breach involving a former employee who accessed electronic medical records without authorization after her employment ended on March 2, 2020. The breach was discovered during a routine audit on March 11, 2020. Affected data included names, DOBs, SSNs, and PHI. The company revoked access, offered one year of credit monitoring, and confirmed the employee destroyed the data.
California clockDiscovered Mar 11, 2020 → Notified Apr 1, 202021d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-189210
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 16, 2020
- Raw hash
- c501d9b9ecca77a6e702b23acbc26fb89e5d920ceaecf7f5b162a5c5f0d4c434
Reporting entity
- Name
- Grimaldi Center for Wellness and Aestheticsnorm: grimaldi center for wellness and aesthetics
Victim entity
- Name
- Grimaldi Center for Wellness and Aestheticsnorm: grimaldi center for wellness and aesthetics
Incident
- Discovered
- Mar 11, 2020
- Materiality determined
- —
- Notification sent
- Apr 1, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- insider_action
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 11, 2020→ Notified: Apr 1, 202021d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.