County of Los Angeles Department of Public Health
ent_8b26b3443faacf48fcc3f787
Disclosures
5
State AG · HHS OCR · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
252,856
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- County of Los Angeles Department of Public Health
- Normalized
- county of los angeles department of public health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2024-06-21
Los Angeles County Department of Health Services filed a breach notification with the California OAG. The date of breach listed is February 6, 2024. The consumer notification letter attachment could not be extracted (pages returned empty). Minimal details are available from the filing page alone.
- 🐻California State AGas victim2024-06-14
Los Angeles County Dept of Public Health experienced a phishing attack between Feb 19-20, 2024, where an external actor gained credentials for 53 employees via a malicious link. Compromised data may include names, DOB, SSN, diagnoses, prescriptions, medical record numbers, and insurance info. DPH disabled accounts, reset devices, and offered one year of identity monitoring via Kroll. Law enforcement was notified.
- CALIFORNIAHHS OCRas victim2024-04-25
County of Los Angeles Departments of Health Services and Public Health reported to HHS on 2024-04-25 a Hacking/IT Incident (email phishing scheme) affecting 252,856 individuals. Multiple employees were targeted via phishing, exposing PHI including names, addresses, dates of birth, driver's license and Social Security numbers, financial information, diagnoses, conditions, lab results, medications, and other treatment information. Breached information located on Email. The CE notified affected individuals, media, and HHS, and offered credit monitoring. Staff were retrained on email security and additional technical safeguards were implemented.
- 🐻California State AGas victim2024-04-25
Los Angeles County Department of Health Services experienced a phishing attack between February 19-20, 2024, where hackers obtained login credentials for 23 employee email accounts via malicious links. Compromised data included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and health information (diagnoses, treatments, medications). SSNs and financial information were not involved. DHS disabled accounts, reset devices, blocked phishing sites, and notified law enforcement and regulators (CDPH, HHS OCR).
- 🐻California State AGas victim2022-08-23
County of Los Angeles Department of Public Health disclosed a data breach involving the unauthorized public posting of Mobile Food Facility Official Inspection Reports on its Environmental Health Division website. The reports, posted between July 1, 2020, and July 29, 2022, contained individuals' names and driver's license or identification numbers. The agency removed the reports and provided additional staff training.