Verity Medical Foundation
ent_6ef6ab0e4321acef9e41bf40
Disclosures
5
State AG · HHS OCR · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
14,894
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Verity Medical Foundation
- Normalized
- verity medical— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sanjosemed.com
Disclosure history (5)newest first
- 🐻California State AGas victim2019-03-22
On January 16, 2019, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for several hours. The attacker sent emails with malicious links to obtain credentials. The intruder had access to email folders containing health information, including names, dates of birth, SSNs, driver's licenses, and treatment details. VMF terminated access, disabled accounts, and offered one year of credit monitoring. No financial account numbers were accessed.
- CALIFORNIAHHS OCRas victim2019-03-07
Verity Medical Foundation (CA healthcare provider) reported to HHS OCR on 2019-03-07 a Hacking/IT Incident affecting 14,894 individuals. An unauthorized third party accessed a workforce member's email account. PHI exposed included demographic, clinical, health plan claims, and payment information. The entity notified HHS, affected individuals, and media, and subsequently implemented anti-phishing technical controls and workforce training. OCR documented voluntary corrective action.
- 🐻California State AGas victim2019-01-28
On November 28, 2018, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for approximately 1.5 hours. The attacker sent emails with malicious Docusign links to obtain credentials. The intruder had access to the employee's email folders, which contained personal information including names, dates of birth, social security numbers, phone numbers, and addresses. The Foundation terminated access, disabled the account, and offered one year of credit monitoring.
- 🐻California State AGas victim2017-02-07
Verity Medical Foundation notified California AG of unauthorized access to a decommissioned website (Oct 2015–Jan 2017). Patient data exposed: names, DOBs, MRNs, contact info, partial credit card digits. No SSNs or full card numbers. No misuse known. Remediation: credit monitoring via Equifax.
- CALIFORNIAHHS OCRas victim2017-01-11
Verity Medical Foundation (CA) reported to HHS on 2017-01-11 a Hacking/IT Incident affecting 10,164 individuals. One of its websites (www.sanjosemed.com) was compromised and used to distribute malware to visitors. Affected individuals were patients of San Jose Medical Group (joined 2017). PHI involved: names, addresses, dates of birth, medical record numbers, and last 4 digits of credit card numbers. Breached information located on Network Server. Website was immediately disabled upon discovery; notifications sent to HHS, individuals, and media. OCR obtained corrective-action assurances.