MalwareRansomwareStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Scripps Health
bd_c6218ed1fd4821f8 · schema v1 · pii pii-v1
Full breach record for Scripps Health →Scripps Health reported a cybersecurity incident where an unauthorized person gained access to its network, deployed malware, and acquired copies of documents containing patient PII and PHI. The incident occurred on April 29, 2021, and was discovered on May 1, 2021. Affected data included names, addresses, DOBs, SSNs, driver's licenses, and medical records. No fraud indication was found. Remediation included security enhancements and credit monitoring offers.
California clockDiscovered May 1, 2021 → Notified May 1, 20210d ✓ CA 60-day OK4 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_af8f52b4413f4125HHS OCRfiled 2021-06-01Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541472
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2021
- Raw hash
- 97653e5fdd0a87f401314c7641a91344e824bb8da2327fe0601daa517425085a
Reporting entity
- Name
- Scripps Healthnorm: scripps health
Victim entity
- Name
- Scripps Healthnorm: scripps health
Incident
- Discovered
- May 1, 2021
- Materiality determined
- May 1, 2021
- Notification sent
- May 1, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 1, 2021→ Notified: May 1, 20210d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.