SAC Health System
ent_0bd7b280acf60921be532d35
Disclosures
4
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
77,842
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SAC Health System
- Normalized
- sac health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- CALIFORNIAHHS OCRas victim2022-05-05
SAC Health System (CA) reported to HHS on 2022-05-05 a Theft affecting 77,842 individuals. A break-in occurred at the covered entity's paper record storage facility, compromising PHI including names, addresses, dates of birth, diagnoses, and conditions (Paper/Films). The CE notified HHS, affected individuals, the media, and provided substitute notice. Credit monitoring services were offered and additional administrative and physical safeguards were implemented.
- CALIFORNIAHHS OCRas victim2021-05-10
SAC Health Systems (CA, Healthcare Provider) reported to HHS on 2021-05-10 that its business associate experienced a ransomware attack affecting the ePHI of 28,128 individuals. Breached information was located on a Network Server. Exposed data included names, addresses, Social Security numbers, financial and health insurance information, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media, and subsequently terminated its relationship with the affected BA.
- California State AGas victim2021-05-10
SAC Health System notified individuals that a third-party service provider, Netgain Technology, LLC, experienced a data security incident resulting in unauthorized access to servers containing SAC Health System's medical record database between November 15, 2020, and November 22, 2020. SAC Health System was notified by Netgain on January 15, 2021. Affected data included names, addresses, Social Security numbers, dates of birth, driver's license numbers, financial account information, and medical history. SAC Health System ceased using Netgain, is removing data from their systems, and is offering credit monitoring.
- Indiana State AGas victim2021-05-07
SAC Health System reported a data breach to the Indiana Attorney General. The breach occurred on 2020-11-15 and was reported on 2021-05-07. 1 Indiana residents were affected. 28,128 individuals affected in total.
Supply-chain cascadesreviewed and confirmed
- SAC Health System’s filing is one of at least 15 in the Netgain Networks supply-chain incident (2021).