MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
FPS Medical Center
bd_c5eae579b7c85400 · schema v1 · pii pii-v1
Full breach record for FPS Medical Center →FPS Medical Center experienced a ransomware incident between February 28 and March 3, 2022. An unknown actor encrypted systems, potentially accessing patient information including names, addresses, DOB, driver's licenses, and PHI. The company notified law enforcement, HHS, and offered Equifax credit monitoring. No evidence of misuse was found, but exfiltration could not be ruled out.
California clockDiscovered Mar 3, 2022 → Notified Apr 25, 202253d ✓ CA 60-day OK9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ae76fe1982bc5306Montana State AGfiled 2022-05-06Verified
- bd_d4881cb3fc5243cdMaine State AGfiled 2022-05-06Verified
- bd_3bf201148f80f3e3HHS OCRfiled 2022-05-02(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553197
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2022
- Raw hash
- 7ec47b92038a2ca4588ecb452c88de8c6afb50b32cf94d0f3f9503a7f371f3f3
Reporting entity
- Name
- FPS Medical Centernorm: fps medical center
- Domain
- fpsmedical.net
- Industry
- healthcare
Victim entity
- Name
- FPS Medical Centernorm: fps medical center
- Domain
- fpsmedical.net
- Industry
- healthcare
Incident
- Discovered
- Mar 3, 2022
- Materiality determined
- —
- Notification sent
- Apr 25, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying appropriate governmental regulators, including the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 53d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 3, 2022→ Notified: Apr 25, 202253d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.