The California Office of the Attorney General reported a data breach involving the San Francisco Department of Public Health on October 3, 2019. The breach occurred between November 2018 and August 2019 due to a computer error at a contracted vendor, Alluma, which resulted in personal information being sent to incorrect addresses. The affected information included names, addresses, application ID numbers, participant ID numbers, medical homes, and Healthy San Francisco renewal dates, but did not include social security numbers or dates of birth.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-183128
TPRM report: https://www.rankiteo.com/company/san-francisco-department-of-public-health
"id": "san1037072725",
"linkid": "san-francisco-department-of-public-health",
"type": "Breach",
"date": "11/2018",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'San Francisco, CA',
'name': 'San Francisco Department of Public Health',
'type': 'Government'}],
'attack_vector': 'Computer Error',
'data_breach': {'personally_identifiable_information': True,
'sensitivity_of_data': 'Medium',
'type_of_data_compromised': ['names',
'addresses',
'application ID numbers',
'participant ID numbers',
'medical homes',
'Healthy San Francisco renewal '
'dates']},
'date_detected': '2019-10-03',
'date_publicly_disclosed': '2019-10-03',
'description': 'A data breach involving the San Francisco Department of '
'Public Health occurred due to a computer error at a '
'contracted vendor, Alluma, resulting in personal information '
'being sent to incorrect addresses.',
'impact': {'data_compromised': ['names',
'addresses',
'application ID numbers',
'participant ID numbers',
'medical homes',
'Healthy San Francisco renewal dates']},
'post_incident_analysis': {'root_causes': 'Computer Error'},
'references': [{'date_accessed': '2019-10-03',
'source': 'California Office of the Attorney General'}],
'title': 'San Francisco Department of Public Health Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Computer Error'}