HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIALMediumContained
Eastern Los Angeles Regional Center
bd_f89c96959611403a · schema v1 · pii pii-v1
Full breach record for Eastern Los Angeles Regional Center →Eastern Los Angeles Regional Center (ELARC) experienced unauthorized access to one employee email account on July 15, 2021. The incident potentially exposed client information including names, Social Security numbers, tax IDs, and medical history/treatment information. ELARC secured the system, engaged cybersecurity specialists, and offered 12 months of identity monitoring via Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_80fb2dfbb907eb37HHS OCRfiled 2021-09-13Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545286
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 13, 2021
- Raw hash
- d87f6803fffb045a02e34cb1f21d69f8e65158621738c91f5a935849891ad888
Reporting entity
- Name
- Eastern Los Angeles Regional Centernorm: eastern los angeles regional center
Victim entity
- Name
- Eastern Los Angeles Regional Centernorm: eastern los angeles regional center
Incident
- Discovered
- Jul 15, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.