County of Los Angeles Department of Mental Health
ent_5c8d2f03ddb86886c18f371c
Disclosures
12
HHS OCR · State AG · 1 jurisdiction
Incidents
4
filings grouped by incident
Max affected reported
749,017
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- County of Los Angeles Department of Mental Health
- Normalized
- county of los angeles department of mental health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- CALIFORNIAHHS OCRas victim2024-09-05
County of Los Angeles Department of Mental Health reported to HHS on 2024-09-05 a Hacking/IT Incident (email phishing attack) affecting 2,334 individuals. An employee was targeted via phishing, compromising PHI including names, addresses, dates of birth, Social Security numbers, and treatment information. Breached information was located on Email. The CE notified HHS, affected individuals, and media, and responded by implementing additional technical safeguards and retraining staff.
- 🐻California State AGas victim2024-08-30
Los Angeles County Department of Mental Health experienced a phishing incident on May 28, 2024, where employees interacted with a malicious email from a trusted partner, leading to compromised Microsoft Office 365 accounts. The breach potentially exposed names, SSNs, DOBs, addresses, phone numbers, medical record numbers, health insurance info, diagnoses, and treatment information. The organization disabled accounts, reset credentials, engaged forensic specialists, and notified law enforcement and Microsoft.
- CALIFORNIAHHS OCRas victim2024-05-20
County of Los Angeles Department of Mental Health reported to HHS on 2024-05-20 a Hacking/IT Incident affecting 1598 individuals. Breached information located on Network Server. An employee was the subject of an email phishing scheme that affected PHI including names, dates of birth, and Social Security Numbers. The entity provided credit monitoring and implemented additional safeguards.
- 🐻California State AGas victim2024-05-17
On March 20, 2024, the Los Angeles County Department of Mental Health experienced a phishing incident where an employee scanned a QR code from a malicious attachment, granting an external actor access to their Microsoft Office 365 account. The incident potentially exposed personal information including names, dates of birth, SSNs, addresses, phone numbers, medical record numbers, health insurance info, and treatment information. The department disabled affected accounts, reset credentials, engaged forensic specialists, and notified law enforcement and Microsoft. No evidence of data misuse was found.
- 🐻California State AGas victim2024-03-22
Los Angeles County Department of Mental Health notified individuals that their personal information may have been accessed following a cyberattack on the City of Gardena Police Department on January 22, 2024. Threat actors exploited a multi-factor authentication vulnerability (push notification spam) to access a GPD employee's Microsoft Office 365 account, then used email exchanges to compromise a DMH employee's account. Affected data includes names, dates of birth, SSNs, addresses, phone numbers, and medical record numbers. No evidence of misuse was found. DMH disabled accounts, reset credentials, engaged forensic specialists, and notified Microsoft.
- CALIFORNIAHHS OCRas victim2024-03-22
County of Los Angeles Department of Mental Health reported to HHS on 2024-03-22 a Hacking/IT Incident affecting 1408 individuals. Breached information located on Email. An employee was phished, compromising PHI including names, addresses, DOB, SSN, and treatment info. CE provided credit monitoring and retrained staff.
- CALIFORNIAHHS OCRas victim2023-12-22
County of Los Angeles Department of Mental Health reported to HHS on 2023-12-22 a Hacking/IT Incident affecting 1,284 individuals. An employee was targeted by an email phishing scheme that compromised PHI stored on a network server. Exposed data included names, addresses, dates of birth, Social Security numbers, and treatment information. The CE notified affected individuals, the media, and HHS, provided substitute notice and credit monitoring, and retrained staff on email security.
- 🐻California State AGas victim2023-12-21
Los Angeles County Department of Mental Health notified the CA AG of a breach stemming from a cyber-attack on the Department of Children's and Family Services (DCFS) on Oct 17, 2023. Attackers used MFA push notification spamming to access a DCFS employee's Microsoft 365 account, then leveraged email exchanges to compromise a DMH employee's account. Affected data includes names, DOBs, SSNs, addresses, phone numbers, medical record numbers, health insurance info, diagnoses, and treatment info. DMH disabled accounts, reset credentials, engaged forensics, and implemented new security controls.
- 🐻California State AGas victim2022-04-20
Los Angeles County Department of Mental Health experienced a phishing incident on October 19, 2021, where three employee email accounts were compromised via malicious links. The incident potentially exposed personal information including names, addresses, SSNs, driver's licenses, medical/health information, and financial account numbers. The organization notified law enforcement, reset credentials, and deployed additional security measures. Notification was delayed at the request of law enforcement.
- CALIFORNIAHHS OCRas victim2022-04-20
County of Los Angeles Department of Mental Health reported to HHS on 2022-04-20 a Hacking/IT Incident (email phishing attack) affecting 5,129 individuals. An employee was the victim of a phishing attack compromising PHI including names, addresses, dates of birth, Social Security numbers, diagnoses, and other treatment information. Breached information located on Email. The CE notified HHS, affected individuals, and the media, implemented additional safeguards, and offered credit monitoring. OCR provided technical assistance.
- 🐻California State AGas victim2017-11-13
On October 24, 2017, an employee of the Los Angeles County Department of Mental Health inadvertently emailed a spreadsheet containing job candidates' names, email addresses, and Social Security Numbers to other candidates. The department notified affected individuals on November 13, 2017, and offered one year of free credit monitoring. The incident was classified as an accidental misdelivery of personal identifiable information.
- CALIFORNIAHHS OCRas victim2016-12-16
County of Los Angeles Departments of Health and Mental Health reported to HHS on 2016-12-16 a Hacking/IT Incident affecting 749,017 individuals. Breached information located on Email. Employee email accounts were breached in a phishing attack affecting ePHI. Law enforcement was notified, individuals were alerted, and a third-party security audit was conducted. Remediation included blocking malicious emails, enhanced authentication, and credit monitoring.