MalwareRansomwareData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Pomona Valley Hospital Medical Center
bd_e239572e227ca8ea · schema v1 · pii pii-v1
Full breach record for Pomona Valley Hospital Medical Center →Pomona Valley Hospital Medical Center notified patients of a security incident at a vendor's subcontractor. In late November 2023, an unauthorized third party accessed a patient-management tool and encrypted files containing protected health information (PHI), including names, medical record numbers, dates of birth, and clinical details. The hospital confirmed the breach on February 1, 2024, after the vendor provided additional information. The hospital engaged third-party experts, stopped using the affected vendor, and is assisting impacted individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b4a7ed8551649528Montana State AGfiled 2024-03-22Verified
- bd_f77d0fe48b631e8cHHS OCRfiled 2024-03-20(2d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582882
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2024
- Raw hash
- e1ed8a84062315a4fd78b923469c7145481b950c68f2292c8ce87cb61ae6ccf8
Reporting entity
- Name
- Pomona Valley Hospital Medical Centernorm: pomona valley hospital medical center
- Domain
- pvhmc.org
Victim entity
- Name
- Pomona Valley Hospital Medical Centernorm: pomona valley hospital medical center
- Domain
- pvhmc.org
Incident
- Discovered
- Nov 27, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Vendor's Subcontractor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.