DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDMediumContained

SUTTER HEALTH

bd_fb510492a16fda0b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 5, 2017

Filed

Feb 7, 2018

To disclose

9 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for SUTTER HEALTH →3 incidents on file

Sutter Health notified individuals that a vendor, Salem and Green, was impacted by a phishing attack allowing unauthorized access to email systems on October 11-12, 2017. Sutter Health learned of the incident on December 5, 2017. The accessed data included names, dates of birth, SSNs, and driver's license numbers for individuals affiliated with Sutter Health involved in M&A activities. Salem and Green retained forensics, enhanced security procedures, implemented MFA, and provided staff training. Sutter Health offered one year of Experian credit monitoring.

California clockDiscovered Dec 5, 2017 → Notified Feb 6, 201863d ✗ CA 60-day late9 weeks discovery → filing

Incident timeline

undetected · 55 days
discovery → filing · 9 weeks / 64 days

Oct 11, 2017

Begins

Dec 5, 2017

Discovered

Feb 7, 2018

Filed

vs. sector median

on median

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.