Verity Medical Foundation
ent_6ef6ab0e4321acef9e41bf40
Disclosures
6
State AG · HHS OCR · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
14,894
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Verity Medical Foundation
- Normalized
- verity medical— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sanjosemed.com
Disclosure history (6)newest first
- California State AGas victim2019-03-22
On January 16, 2019, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for several hours. The attacker sent emails with malicious links to obtain credentials. The intruder had access to email folders containing health information, including names, dates of birth, SSNs, driver's licenses, and treatment details. VMF terminated access, disabled accounts, and offered one year of credit monitoring. No financial account numbers were accessed.
- CALIFORNIAHHS OCRas victim2019-03-07
Verity Medical Foundation (CA healthcare provider) reported to HHS OCR on 2019-03-07 a Hacking/IT Incident affecting 14,894 individuals. An unauthorized third party accessed a workforce member's email account. PHI exposed included demographic, clinical, health plan claims, and payment information. The entity notified HHS, affected individuals, and media, and subsequently implemented anti-phishing technical controls and workforce training. OCR documented voluntary corrective action.
- Massachusetts State AGas victim2019-02-04
Verity Medical Foundation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-02-04. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-01-28
On November 28, 2018, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for approximately 1.5 hours. The attacker sent emails with malicious Docusign links to obtain credentials. The intruder had access to the employee's email folders, which contained personal information including names, dates of birth, social security numbers, phone numbers, and addresses. The Foundation terminated access, disabled the account, and offered one year of credit monitoring.
- California State AGas victim2017-02-07
Verity Medical Foundation disclosed that an unauthorized third party accessed a decommissioned website (Verity Medical Foundation-San Jose Medical Group) between October 2015 and January 2017. The organization detected the breach on January 6, 2017. Affected data includes patient names, dates of birth, medical record numbers, addresses, email addresses, phone numbers, and the last four digits of credit card numbers. Social security numbers and full credit card information were not involved. The organization engaged a cybersecurity firm, secured the website, and offered credit monitoring.
- CALIFORNIAHHS OCRas victim2017-01-11
Verity Medical Foundation (CA) reported to HHS on 2017-01-11 a Hacking/IT Incident affecting 10,164 individuals. One of its websites (www.sanjosemed.com) was compromised and used to distribute malware to visitors. Affected individuals were patients of San Jose Medical Group (joined 2017). PHI involved: names, addresses, dates of birth, medical record numbers, and last 4 digits of credit card numbers. Breached information located on Network Server. Website was immediately disabled upon discovery; notifications sent to HHS, individuals, and media. OCR obtained corrective-action assurances.