HackingPhishingStolen CredentialsData ExfiltratedData PublishedCustomer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Stockton Cardiology Medical Group
bd_c894ddefa9738b82 · schema v1 · pii pii-v1
Full breach record for Stockton Cardiology Medical Group →Stockton Cardiology Medical Group notified patients of a data breach on March 9, 2026. On December 15, 2025, suspicious emails were identified. On January 17, 2026, it was discovered that an unauthorized individual accessed and removed files containing PHI and PII. On February 17, 2026, some files were publicly disclosed. The group engaged a security firm, shut down remote access, added MFA, and reset passwords. Credit monitoring is offered.
California clockDiscovered Jan 17, 2026 → Notified Mar 9, 202651d ✗ CA 30-day late7 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-620623
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2026
- Raw hash
- 3933c918189646bb27aa0e5d97a81909c1c1b5ecd1bd2332ae79ccc95da6d3d4
Reporting entity
- Name
- Stockton Cardiology Medical Groupnorm: stockton cardiology medical
- Domain
- stocktoncardiology.com
Victim entity
- Name
- Stockton Cardiology Medical Groupnorm: stockton cardiology medical
- Domain
- stocktoncardiology.com
Incident
- Discovered
- Jan 17, 2026
- Materiality determined
- —
- Notification sent
- Mar 9, 2026
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1041 Exfiltration Over C2 ChannelT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- CA 30-day late · 51dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 17, 2026→ Notified: Mar 9, 202651d 30 calendar days CA 30-day late California Consumers notified: Mar 9, 2026→ AG copy submitted: Mar 9, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.