HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTPHIMediumContained
Valley Mountain Regional Center
bd_dfd449502298c885 · schema v1 · pii pii-v1
Full breach record for Valley Mountain Regional Center →Valley Mountain Regional Center notified individuals of a data breach where personal information, including names and Social Security numbers, and personal health information were acquired without authorization on or about July 29, 2023. The organization became aware of unusual activity on August 1, 2023. The incident was reported to the FBI, and 12 months of credit monitoring and fraud assistance are being provided to affected individuals.
California clockDiscovered Aug 1, 2023 → Notified Apr 19, 2024262d ✗ CA 60-day late37 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5c08fd6ae8156959Indiana State AGfiled 2024-04-19Verified
- bd_62be608eb7747666Oregon State AGfiled 2024-04-19Candidate
- bd_6ae0c34d4c9b5537New Hampshire State AGfiled 2024-04-19Verified
- bd_828e5ed96afbae42Montana State AGfiled 2024-04-19Verified by operator
Show 1 more filing ↓Show fewer ↑
- bd_953affa4774a50d7Vermont State AGfiled 2024-04-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-584180
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 19, 2024
- Raw hash
- 807908f2658aad4f5e4ef8c551156259e50ed31e046c340af98092b9d0173970
Reporting entity
- Name
- Valley Mountain Regional Centernorm: valley mountain regional center
- Domain
- vmrc.net
Victim entity
- Name
- Valley Mountain Regional Centernorm: valley mountain regional center
- Domain
- vmrc.net
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- Apr 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to the FBI
Compliance
- Time to disclose
- 37 weeks(262 days from discovery to filing)
- Compliance flags
- CA 60-day late · 262dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2023→ Notified: Apr 19, 2024262d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.