Cyber Incident Victim: Verity Health System of California, Inc.
Timeline
Summary
Verity Medical Foundation experienced a third unauthorized access incident involving employee email accounts, compromising protected health information for over 14,000 patients. The breach was detected within hours, mirroring two prior similar incidents disclosed shortly beforehand. In response, the organization implemented enhanced security measures including mandatory password resets, disabled unknown URLs, conducted targeted employee re-education, and deployed new organization-wide cybersecurity training modules. Four distinct notification templates were used to inform affected individuals of the breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 16, 2019, Verity Medical Foundation experienced a third unauthorized access incident involving an employee's email account containing protected health information (PHI), occurring less than two weeks after disclosing two similar breaches in January 2019. The intrusion was detected within hours of occurrence, mirroring the rapid discovery timeline of the prior incidents. The compromised email account stored or had attachments containing PHI, though the specific data elements or attacker methods were not disclosed. This event impacted over 14,000 patients, as subsequently listed on the HHS breach reporting tool in March 2019. The breach represented a recurring pattern, as all three January 2019 incidents involved employee email account compromises exposing PHI through identical attack vectors. No evidence suggested prolonged access or systemic network infiltration beyond the targeted email accounts.

Verity Medical Foundation responded by implementing corrective measures including individualized counseling and security re-education for involved personnel. The organization deployed a new mandatory training module for all employees and initiated security enhancements, notably system-wide password resets and the disabling of unknown URLs. Four distinct notification letter templates were issued to affected parties, though the specific content variations or recipient segmentation criteria were not detailed. The foundation did not disclose whether forensic investigations linked the three January breaches to a common threat actor or whether regulatory penalties were imposed. The cumulative impact of these incidents revealed persistent vulnerabilities in email account security practices despite prior remediation efforts.
