Social EngineeringPhishingCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Health Plan of San Mateo
bd_de9fe860bf4d3e2c · schema v1 · pii pii-v1
Full breach record for Health Plan of San Mateo →Health Plan of San Mateo disclosed an email phishing incident on January 17, 2023, where an unauthorized person accessed one employee email account. The attacker attempted to fraudulently change direct deposit information. A spreadsheet containing member names, dates of birth, member IDs, and limited nurse advice line call information was potentially exposed. No SSNs or financial data were involved. The company engaged a cybersecurity firm, reviewed the mailbox, enhanced security measures, and provided employee training.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_832929322c4b59cbHHS OCRfiled 2023-03-17Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564499
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2023
- Raw hash
- c156e233adf23d19a57492a810b26e5f090505dbc409bb808b23d21edd293fe8
Reporting entity
- Name
- Health Plan of San Mateonorm: health plan of san mateo
Victim entity
- Name
- Health Plan of San Mateonorm: health plan of san mateo
Incident
- Discovered
- Jan 17, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.