HackingStolen CredentialsPhishingCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Verity Medical Foundation
bd_f67b53e7e1144e07 · schema v1 · pii pii-v1
Full breach record for Verity Medical Foundation →On January 16, 2019, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for several hours. The attacker sent emails with malicious links to obtain credentials. The intruder had access to email folders containing health information, including names, dates of birth, SSNs, driver's licenses, and treatment details. VMF terminated access, disabled accounts, and offered one year of credit monitoring. No financial account numbers were accessed.
California clockDiscovered Jan 16, 2019 → Notified Mar 11, 201954d ✓ CA 60-day OK9 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-145668
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2019
- Raw hash
- afcab2ec2b03d107406cc6ac628157099a670ad2da97ce26549509ca267c76bc
Reporting entity
- Name
- Verity Medical Foundationnorm: verity medical
- Domain
- sanjosemed.com
Victim entity
- Name
- Verity Medical Foundationnorm: verity medical
- Domain
- sanjosemed.com
Incident
- Discovered
- Jan 16, 2019
- Materiality determined
- —
- Notification sent
- Mar 11, 2019
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 54d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 16, 2019→ Notified: Mar 11, 201954d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.