SUTTER HEALTH
bd_fb510492a16fda0b · schema v1 · pii pii-v1
Full breach record for SUTTER HEALTH →3 incidents on fileSutter Health notified individuals that a vendor, Salem and Green, was impacted by a phishing attack allowing unauthorized access to email systems on October 11-12, 2017. Sutter Health learned of the incident on December 5, 2017. The accessed data included names, dates of birth, SSNs, and driver's license numbers for individuals affiliated with Sutter Health involved in M&A activities. Salem and Green retained forensics, enhanced security procedures, implemented MFA, and provided staff training. Sutter Health offered one year of Experian credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 11, 2017
Begins
Dec 5, 2017
Discovered
Feb 7, 2018
Filed
vs. sector median
on median
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.