Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Alameda Health System
bd_e787e8baa176312c · schema v1 · pii pii-v1
Full breach record for Alameda Health System →Alameda Health System notified California AG in 2022 regarding unauthorized access to employee email accounts from May 2020 to March 2022. The breach exposed patient PII, including names, SSNs, driver's license numbers, and clinical/insurance data. AHS engaged forensic investigators and offered one year of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554583
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2022
- Raw hash
- 6d948fc21b59c6a202ba222f339c8d6e9e48b8ef1068a9ed89af5ee358828cb4
Reporting entity
- Name
- Alameda Health Systemnorm: alameda health system
Victim entity
- Name
- Alameda Health Systemnorm: alameda health system
Incident
- Discovered
- Feb 23, 2022
- Materiality determined
- Jun 24, 2022
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.