HackingSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICLowContained
Sutter North Surgery Center
bd_d8ebf2f35ab81bb7 · schema v1 · pii pii-v1
Full breach record for Sutter North Surgery Center →Sutter North Surgery Center notified California residents that their protected health information may have been accessed by an unauthorized actor via its vendor, Sightpath Medical, LLC. Sightpath discovered unusual activity on February 9, 2022, and determined PHI was involved on June 14, 2023. The incident is contained. Complimentary identity protection services are offered.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7ded52559e476f08HHS OCRfiled 2023-09-08Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-573050
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 8, 2023
- Raw hash
- 6d24be6b816d986930bea0e0502f7cc75d3c96be820da8613679cfbe1bf17abd
Reporting entity
- Name
- Sutter North Surgery Centernorm: sutter north surgery center
Victim entity
- Name
- Sutter North Surgery Centernorm: sutter north surgery center
Incident
- Discovered
- Feb 9, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Sightpath Medical, LLC
Compliance
- Time to disclose
- 19 months(576 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.