HackingData ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)PHIHEALTH_BASICIDENTITY_BASICLowContained
Clinical Registry Solutions
bd_cf661af5a4e58e57 · schema v1 · pii pii-v1
Full breach record for Clinical Registry Solutions →Clinical Registry Solutions (CRS), a vendor providing registry support services to Dignity Health – St. Mary's Medical Center, discovered unauthorized access to its network on April 9, 2026. The incident involved the acquisition of files containing patient information, including names, medical record numbers, and procedure dates. CRS secured its network, investigated the scope, and notified affected individuals. No evidence of misuse was found.
Leak gap clock⏱ Leak >30d9 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_f828cc6ad7ec7eccLeak Siteakirafiled 2026-05-06(36d gap)Verified
- bd_401d01df51fe3e5fLeak Siteakirafiled 2026-04-09(63d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_f331216109245cf4New Hampshire State AGfiled 2026-06-11Verified
- bd_fe5df6567cc5082dHHS OCRfiled 2026-06-12(1d gap)Verified
- bd_8e3980e02c3b30f2Indiana State AGfiled 2026-06-17(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624728
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2026
- Raw hash
- 415e5145b73d72ec7aeeb38792752f6d2744e2936ae6d6e4767fcab123a2348a
Reporting entity
- Name
- Clinical Registry Solutionsnorm: clinical registry
- Domain
- clinicalregistrysolutions.com
Victim entity
- Name
- Clinical Registry Solutionsnorm: clinical registry
- Domain
- clinicalregistrysolutions.com
Incident
- Discovered
- Apr 9, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.