HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Salinas Valley Memorial Healthcare System
bd_f3a47a46665d2ac7 · schema v1 · pii pii-v1
Full breach record for Salinas Valley Memorial Healthcare System →Salinas Valley Memorial Healthcare System (SVMHS) experienced a cyber incident where five email accounts (one employee, one contractor, three employees) were compromised via Outlook Web Access. The breach was discovered on April 30, 2020, with the occurrence date listed as April 29, 2020. Affected data included PHI such as names, medical record numbers, service locations, and attending physician information. SVMHS disabled access, reset passwords, implemented MFA, and offered one year of Experian IdentityWorks. No evidence suggests data was viewed or copied.
California clockDiscovered Apr 30, 2020 → Notified Jun 29, 202060d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_365713df4ac39cb2California State AGfiled 2020-07-29(30d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-191525
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2020
- Raw hash
- c5a881702ddff3ea6405b21ba9f86654aa4297783177035e3b49181992726c0a
Reporting entity
- Name
- Salinas Valley Memorial Healthcare Systemnorm: salinas valley memorial healthcare system
Victim entity
- Name
- Salinas Valley Memorial Healthcare Systemnorm: salinas valley memorial healthcare system
Incident
- Discovered
- Apr 30, 2020
- Materiality determined
- —
- Notification sent
- Jun 29, 2020
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified the California Department of Public HealthNotifying the California Attorney GeneralNotifying the U.S. Department of Health and Human Services Office for Civil Rights
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 30, 2020→ Notified: Jun 29, 202060d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.