County of Los Angeles Department of Public Health
bd_f2c63a71a483e319 · schema v1 · pii pii-v1
Full breach record for County of Los Angeles Department of Public Health →County of Los Angeles Departments of Health Services and Public Health reported to HHS on 2024-04-25 a Hacking/IT Incident (email phishing scheme) affecting 252,856 individuals. Multiple employees were targeted via phishing, exposing PHI including names, addresses, dates of birth, driver's license and Social Security numbers, financial information, diagnoses, conditions, lab results, medications, and other treatment information. Breached information located on Email. The CE notified affected individuals, media, and HHS, and offered credit monitoring. Staff were retrained on email security and additional technical safeguards were implemented.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f483ba0f0ae3054aCalifornia State AGfiled 2024-04-25Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 25, 2024
- Raw hash
- 853962ca2a67c2589e6f6d6dbdfa6d7d801bbf5fe2563972b40b5c3c1b4e823e
Source filing
Reporting entity
- Name
- County of Los Angeles Department of Public Healthnorm: county of los angeles department of public health
- Industry
- Health Care Services
Victim entity
- Name
- County of Los Angeles Department of Public Healthnorm: county of los angeles department of public health
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 252,856
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified HHS
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.