HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
El Centro Regional Medical Center (ECRMC)
bd_c95d376245867601 · schema v1 · pii pii-v1
Full breach record for El Centro Regional Medical Center (ECRMC) →El Centro Regional Medical Center (ECRMC) reported a data breach involving its third-party vendor, Jobscience. Between May 8 and May 11, 2018, an unknown third party stole electronic information from Jobscience's servers containing job applicant data, including names, addresses, phone numbers, dates of birth, usernames, passwords, email addresses, and Social Security Numbers. ECRMC engaged forensic investigators and the FBI. Affected individuals were offered 24 months of credit monitoring.
California clockDiscovered Aug 1, 2018 → Notified Oct 1, 201861d ✗ CA 60-day late16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f8d0afcabb7a1615Montana State AGfiled 2018-11-16(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141928
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2018
- Raw hash
- 3bd6b8c67cbc89b0c86756445f4119de59d7695e207b8f1dd78217290f15114d
Reporting entity
- Name
- El Centro Regional Medical Center (ECRMC)norm: el centro regional medical center ecrmc
Victim entity
- Name
- El Centro Regional Medical Center (ECRMC)norm: el centro regional medical center ecrmc
Incident
- Discovered
- Aug 1, 2018
- Materiality determined
- —
- Notification sent
- Oct 1, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Office of the Attorney General
- Third party
- via Jobscience
- Initial access
- supply_chain
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- CA 60-day late · 61d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2018→ Notified: Oct 1, 201861d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.