Verity Health System of California, Inc.
ent_c680e5ae0fe2acb5e849ea62
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
2,988
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Verity Health System of California, Inc.
- Normalized
- verity health system of california— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- FEDERALHHS OCRas victim2019-01-26
On January 26, 2019, Verity Health System of California, Inc. reported a hacking incident to HHS affecting 2,988 individuals. An unauthorized third party gained access to an employee's email account containing protected health information, including demographic, clinical, and financial data. The information was located on an email server. In response, the company implemented multi-factor authentication, enhanced password policies, and provided additional workforce training on identifying phishing attempts.
- 🐻California State AGas victim2019-01-25
Verity Health System notified individuals that a third party compromised an employee's Microsoft 365 email account on November 27, 2018. The attacker sent emails with malicious links to obtain credentials. Health information, including SSNs and medical records, may have been accessed from email attachments. VHS acted as a business associate for O'Connor Hospital. The incident was contained, and credit monitoring was offered.
- 🐻California State AGas victim2016-05-31
Verity Health System experienced a phishing incident on April 27, 2016, where an employee was targeted by a scammer impersonating a Verity executive. The employee disclosed names, addresses, Social Security numbers, and W-2 earnings information for current and former employees. No patient information or systems were breached. Verity notified law enforcement, engaged outside experts, and provided two years of free identity protection services through Equifax to affected employees.