Methodist Hospital of Southern California
Disclosed Nov 4, 20205 years ago39,881 affectedConfirmed
The covered entity (CE), Methodist Hospital of Southern California, reported that its business associate experienced a ransomware attack affecting the electronic protected health information (ePHI) of approximately 39,881individuals. The ePHI involved included names, addresses, dates of birth, and treatment information. This breach involved the CE’s medical foundation, which is not subject to the HIPAA Rules.
What is known
| People affected | 39,881 (as reported to HHS) |
|---|---|
| Disclosed | Nov 4, 2020 |
| Happened | Feb 1, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Methodist Hospital of Southern Californiaoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Methodist Hospital of Southern California (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Nov 4, 2020 | |
| HHS archivetotal | Nov 4, 2020 | 39,881 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 39881 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Methodist Hospital of Southern California, reported that its business associate experienced a ransomware attack affecting the electronic protected health information (ePHI) of approximately 39,881individuals. The eP · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.