Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
UnityPoint Health
bd_fb9da4101eacad04 · schema v1 · pii pii-v1
Full breach record for UnityPoint Health →California AG breach notification for UnityPoint Health regarding a phishing attack on business email systems between March 14 and April 3, 2018, discovered May 31, 2018. Attackers obtained credentials via phishing emails, accessing accounts containing patient PHI and PII (SSN, DOB, financial data). No known misuse reported. Remediation included password resets, MFA, employee training, and free credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_799993f34d0de7d6HHS OCRfiled 2018-07-30Verified
- bd_f8f71ff026792fffMontana State AGfiled 2018-07-30Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138399
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 30, 2018
- Raw hash
- f0c08c3c8839329c56284c779ae3a2506e0b72dce0591bb1bad5d5a1400e640f
Reporting entity
- Name
- UnityPoint Healthnorm: unitypoint health
- Domain
- unitypoint.org
Victim entity
- Name
- UnityPoint Healthnorm: unitypoint health
- Domain
- unitypoint.org
Incident
- Discovered
- May 31, 2018
- Materiality determined
- Apr 3, 2018
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.