SUTTER HEALTH
ent_019e0c0700a14bde3be601591d1b8c29
Disclosures
3
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
845,441
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SUTTER HEALTH
- Normalized
- sutter health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300MJCC12LU768G81
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sutterhealth.org
Disclosure history (3)newest first
- 🐻California State AGas victim2023-11-03
Sutter Health notified patients of a data breach involving its third-party vendor, Welltok, Inc. An unknown actor exploited software vulnerabilities in Welltok's MOVEit Transfer server on May 30-31, 2023, exfiltrating data including names and other personal information. Welltok was alerted on July 26, 2023, and confirmed the compromise on August 11, 2023. Affected individuals are offered credit monitoring and identity restoration services.
- CALIFORNIAHHS OCRas victim2023-11-03
Sutter Health reported to HHS on 2023-11-03 a Hacking/IT Incident affecting 845,441 individuals. Breached information located on Network Server. A business associate experienced a malware attack affecting PHI including names, addresses, DOB, and diagnoses. CE provided credit monitoring and implemented safeguards.
- 🐻California State AGas victim2018-02-07
Sutter Health notified California AG that vendor Salem and Green was compromised via a phishing attack on October 11-12, 2017. The attacker accessed email containing PII (SSN, DOB, driver's license) of Sutter-affiliated individuals. Sutter offered one year of Experian credit monitoring. Remediation included MFA and staff training.