Two very different California providers are mailing notices this week: a 12-bed rural hospital that a ransomware crew says it raided, and a Los Angeles nonprofit that helps children and families.
An intruder sat inside a rural hospital’s network for eight days. Staff at Modoc Medical Center in Alturas spotted the access on January 27 and traced it back to January 19, finding that certain patient files had been downloaded. Notices are going out with 12 to 24 months of credit monitoring attached. The Worldleaks extortion group has claimed the attack; it is not clear whether files were encrypted.
A Los Angeles nonprofit serving children and families is the second notifier. Vista Del Mar Child and Family Services flagged suspicious activity on June 30, and outside investigators confirmed an unauthorized party reached systems holding personal and protected health information. Services carried on without interruption, but the nonprofit is still reviewing the data and cannot yet say how many people are affected or which data types were reached. It reported the incident to the Office for Civil Rights as involving at least 500 individuals.
For small and mid-sized providers, the pair illustrates two constants: intrusion dwell time measured in days, and disclosure timelines measured in months. Both organizations said they have tightened monitoring and controls.