Regal Medical Group,Lakeside Medical Organization, ADOC Acquisition, & Greater Covina Medical Group Data Breach
Major California Medical Groups Hit by Network Server Breach
What happened in the Regal Medical Group,Lakeside Medical Organization, ADOC Acquisition, & Greater Covina Medical Group data breach?
The Regal Medical Group,Lakeside Medical Organization, ADOC Acquisition, & Greater Covina Medical Group data breach was reported on February 1, 2023 and affected 3,388,856 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in California. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Regal Medical Group,Lakeside Medical Organization, ADOC Acquisition, & Greater Covina Medical Group Breach Details
On February 1, 2023, a significant data breach was reported affecting four affiliated California medical organizations: Regal Medical Group, Lakeside Medical Organization, ADOC Acquisition, and Greater Covina Medical Group. The breach resulted from unauthorized access to network servers, compromising the protected health information (PHI) of approximately 3.39 million individuals. This incident represents one of the largest healthcare data breaches in California in recent years, affecting patients across multiple medical facilities and service areas throughout the state.
Company Response
Upon discovery of the unauthorized access to their network infrastructure, the affected medical organizations initiated a comprehensive investigation to determine the scope and nature of the breach. The entities worked to identify which patient records were accessed, what specific data elements were compromised, and the timeframe during which the unauthorized access occurred. Following standard HIPAA breach notification requirements, the organizations began the process of notifying affected individuals of the incident. The submission date of February 1, 2023, indicates that the breach was reported to the California Attorney General and likely to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights within the mandated 60-day notification window.
Specific Details
The breach occurred at the network server level, which typically indicates that attackers gained unauthorized access to centralized systems where patient data is stored and processed. Network server compromises of this magnitude suggest either sophisticated hacking techniques, exploitation of unpatched vulnerabilities, or potential credential compromise. The attackers may have used methods such as phishing attacks targeting employee credentials, exploitation of known or zero-day vulnerabilities in network infrastructure, weak authentication mechanisms, or lateral movement through the network once initial access was obtained. The fact that this breach affected multiple affiliated organizations suggests either a coordinated attack across the healthcare system or a single point of compromise that provided access to interconnected networks serving all four entities.
Organizational Context
The affected entities represent a significant healthcare delivery network in California. Regal Medical Group, Lakeside Medical Organization, ADOC Acquisition, and Greater Covina Medical Group collectively operate multiple medical facilities serving patients throughout California. These organizations provide primary care, specialty services, and other healthcare services to a substantial patient population. The interconnected nature of these four organizations—evidenced by their joint breach notification—suggests they may share common IT infrastructure, electronic health record (EHR) systems, or network architecture. This consolidation, while potentially offering operational efficiencies, also created a single point of failure that exposed millions of patient records simultaneously.
Number of People Affected
Approximately 3,388,856 individuals were affected by this breach, making it a breach of extraordinary scale. This figure represents patients who received care at one or more of the four affiliated medical organizations and whose information was stored on the compromised network servers. The affected population likely includes current patients, former patients, and potentially individuals who sought care at these facilities over an extended period. Given the size of the affected population, notification efforts would have been substantial, requiring coordination across multiple organizations and communication channels.
Personal Information Involved
While the specific data elements compromised in this breach have not been detailed in the available information, network server breaches of this nature typically expose multiple categories of protected health information. Likely exposed data may include: patient names, dates of birth, Social Security numbers, medical record numbers, insurance information, healthcare provider identifiers, diagnoses and medical conditions, treatment information, medication records, laboratory results, imaging reports, billing and payment information, and potentially financial account details. The exposure of Social Security numbers combined with healthcare information creates significant identity theft and fraud risks for affected individuals.
Patient Impact and Notifications
The breach notification process for 3.39 million individuals represented a major undertaking. Affected patients were notified of the breach through written correspondence, which is the standard HIPAA requirement. The notifications would have included information about what data was compromised, the date range of potential unauthorized access, steps the organizations were taking to secure their systems, and recommended actions for patients to protect themselves. Given the scale of this breach, the organizations likely also established a dedicated call center or hotline to answer patient questions and provide guidance on protective measures. The breach would have generated significant media attention in California and potentially nationally, given the number of affected individuals.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Regal Medical Group,Lakeside Medical Organization, ADOC Acquisition, & Greater Covina Medical Group Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review medical records and explanation of benefits (EOB) statements from your healthcare providers for unauthorized services, treatments, or charges; contact providers immediately if you identify suspicious activity
Change passwords for any online healthcare portals, insurance accounts, and financial accounts, using strong, unique passwords; enable multi-factor authentication where available
Consider enrolling in credit monitoring and identity theft protection services if offered by the affected organizations; maintain vigilance for suspicious communications, bills, or collection notices for several years following the breach
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More California Breaches
Search all breaches reported in California
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits