MisusePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
Mercy Medical Center Redding
bd_efb106d22d603700 · schema v1 · pii pii-v1
Full breach record for Mercy Medical Center Redding →California SB24 breach notification for Mercy Medical Center Redding (June 2016). A case manager at third-party vendor naviHealth used a false name and nursing license to access patient records. Data exposed included PHI, SSNs, and PII. naviHealth terminated the individual, contacted law enforcement, and offered 12 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62536
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2016
- Raw hash
- e82d1ff2015c7c15e5e151629a764233fbf960825a1a2ae56ea4100cbe772527
Reporting entity
- Name
- Mercy Medical Center Reddingnorm: mercy medical center redding
Victim entity
- Name
- Mercy Medical Center Reddingnorm: mercy medical center redding
Incident
- Discovered
- Jun 6, 2016
- Materiality determined
- Jun 13, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.