Community Memorial Health System
ent_ce05220d802a6fbf8309aee0
Disclosures
4
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
959
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Community Memorial Health System
- Normalized
- community memorial health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🐻California State AGas victim2021-07-16
Guidehouse, on behalf of Community Memorial Health System (Ventura, CA), disclosed a breach of a third-party secure file transfer service in January 2021. The incident compromised patient data including names, dates of birth, member IDs, addresses, and medical information. Guidehouse notified the health system on May 21, 2021, and offered two years of credit monitoring via Experian.
- 🐻California State AGas victim2020-04-27
Community Memorial Health System (CMHS) notified employees of a data breach at third-party vendor PaperlessPay Corporation. DHS alerted PaperlessPay on February 19, 2020 that an unknown individual was selling access to their client database on the dark web. The unauthorized person accessed PaperlessPay's SQL server on February 18, 2020, where CMHS employee pay stub and tax form data was stored, including names, addresses, SSNs, pay/withholdings, and in some cases bank account numbers. CMHS offered one year of free Experian IdentityWorks to affected employees.
- CALIFORNIAHHS OCRas victim2017-09-05
On June 22, 2017, Community Memorial Health System (CA) experienced a phishing incident in which several hundred staff members received phishing emails. One employee working remotely followed the link, compromising her account credentials. The breach affected 959 individuals. Breached information was located in Email systems. The CE notified HHS, affected individuals, and media, disabled remote/mobile access, required credential resets, enforced two-factor authentication, and deployed centralized server log monitoring. OCR obtained corrective action assurances.
- 🐻California State AGas victim2017-09-05
On June 22, 2017, a Community Memorial Health System (CMHS) employee's email account was compromised via a phishing email. The employee detected anomalies on June 23, 2017, prompting a password reset and investigation. CMHS's forensic consultant found indicators suggesting no personal information was accessed, though certainty could not be confirmed. Affected data potentially included patient names, medical record/account numbers, dates of service, health information, and for some patients, SSNs. CMHS offered 24-month identity theft and credit monitoring via AllClear ID.