Verity Health System of California, Inc.
ent_c680e5ae0fe2acb5e849ea62
Disclosures
4
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,988
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Verity Health System of California, Inc.
- Normalized
- verity health system of california— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- CALIFORNIAHHS OCRas victim2019-05-03
Verity Health System of California, Inc. reported to HHS on 2019-05-03 a Hacking/IT Incident affecting 662 individuals. Breached information located on Email. An unauthorized party accessed a workforce member’s email account containing PHI including demographic, clinical, and health plan information.
- CALIFORNIAHHS OCRas victim2019-01-26
On January 26, 2019, Verity Health System of California, Inc. reported a hacking incident to HHS affecting 2,988 individuals. An unauthorized third party gained access to an employee's email account containing protected health information, including demographic, clinical, and financial data. The information was located on an email server. In response, the company implemented multi-factor authentication, enhanced password policies, and provided additional workforce training on identifying phishing attempts.
- California State AGas victim2019-01-25
Verity Health System notified individuals that a third party compromised an employee's Microsoft 365 email account on November 27, 2018. The attacker sent emails with malicious links to obtain credentials. Health information, including SSNs and medical records, may have been accessed from email attachments. VHS acted as a business associate for O'Connor Hospital. The incident was contained, and credit monitoring was offered.
- California State AGas victim2016-05-31
Verity Health System experienced a targeted email phishing scam on April 27, 2016, where an external actor impersonated an executive to request employee information. The incident was discovered on May 22, 2016. Affected data included names, addresses, Social Security numbers, and W-2 earnings/withholding information for current and former employees. No patient information or systems were breached. The company notified law enforcement, engaged outside experts, and offered two years of identity protection services to affected employees.