Watsonville Community Hospital
bd_fd51d9e52c7b09b2 · schema v1 · pii pii-v1
Full breach record for Watsonville Community Hospital →Watsonville Community Hospital experienced unauthorized access to a limited subset of its network between November 25 and November 30, 2024. The hospital became aware of suspicious activity on November 29, 2024. Investigation confirmed that certain files were accessed or downloaded without authorization. Affected data includes names, addresses, and potentially protected health information. The hospital contained the incident by taking systems offline and isolating affected networks. It engaged third-party investigators, notified the FBI and regulators, and is offering credit monitoring to affected individuals.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_66074d82561ed725Maine State AGfiled 2025-10-17(1d gap)Verified by operator
- bd_64d26d9110233feeMontana State AGfiled 2025-10-15(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-612887
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 16, 2025
- Raw hash
- b0debf3440f5feebbe9140d891d1dda48ea1ab9d99d249c9d4be6b2497457e09
Reporting entity
- Name
- Watsonville Community Hospitalnorm: watsonville community hospital
- Domain
- watsonvillehospital.com
Victim entity
- Name
- Watsonville Community Hospitalnorm: watsonville community hospital
- Domain
- watsonvillehospital.com
Incident
- Discovered
- Nov 29, 2024
- Materiality determined
- —
- Notification sent
- Oct 15, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported to the Federal Bureau of InvestigationReported to appropriate state and federal data privacy regulators
Compliance
- Time to disclose
- 46 weeks(321 days from discovery to filing)
- Compliance flags
- CA 60-day late · 320dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 29, 2024→ Notified: Oct 15, 2025320d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.