HackingTargetedPIIIDENTITY_BASICLowContained
Comprehensive Health Services
bd_e11544c13803764e · schema v1 · pii pii-v1
Full breach record for Comprehensive Health Services →Comprehensive Health Services reported a cyber intrusion affecting current and former employees of client agencies. The breach involved unauthorized access to invoicing files pre-dating 2019, potentially exposing personal information. CHS engaged forensic experts, notified the FBI, and implemented enhanced security measures including new EDR tools and penetration testing. Affected individuals were offered credit monitoring.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550966
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2022
- Raw hash
- 781f84b59b8d7542508cdd0f37f95d9bf8d7fca951a0610363c6466d9e00e422
Reporting entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
Victim entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
Incident
- Discovered
- Nov 3, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement, including the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(104 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.