Notice of Data Breach

San Diego American Indian Health Center Notifies Individuals of Data Breach

SAN DIEGO, California.: November 10, 2022 – San Diego American Indian Health Center (“SDAIHC”), a San Diego based non-profit community health center that provides comprehensive dental, behavioral health, and community wellness services to individuals located in San Diego, CA, has learned of a data security incident that may have involved data belonging to current and former individuals served by SDAIHC. This notice serves as an update to our previous substitute notification posted on August 15, 2022.

On May 5, 2022, SDAIHC discovered it was the victim of a sophisticated cybersecurity attack affecting the digital network. SDAIHC took immediate steps to secure the network environment and engaged cybersecurity experts to assist the with an investigation. The investigation determined that an unknown actor gained access to and obtained data from the SDAIHC network without authorization.

The following personal and protected health information may have been involved in the incident: name, address, Social Security number, driver’s license or state identification card number, tribal identification card number, passport number, medical information, health insurance information, and/or date of birth.

As soon as it discovered the incident, SDAIHC took the steps referenced above. SDAIHC also notified the Federal Bureau of Investigation and will provide whatever cooperation is necessary to hold the perpetrators accountable, if possible. SDAIHC takes the security and privacy of personal information in its possession very seriously and is taking additional steps to prevent a similar event from occurring in the future.

To date, SDAIHC is not aware of any evidence of the misuse of any information potentially involved in this incident.  However, beginning on August 15, 2022, SDAIHC mailed notice of this incident to potentially impacted individuals for which SDAIHC had identifiable address information.  SDAIHC then worked diligently with experts to review the impacted data set and identify any additional potentially impacted individuals with address information. That process was completed on October 14, 2022, and on November 10, 2022, SDAIHC provided notice of this incident to those individuals.  In this notification letter, SDAIHC provided information about the incident and about steps that potentially affected individuals can take to protect their information.  SDAIHC also offered individuals access to complimentary credit monitoring and identity protection services through IDX.

SDAIHC has established a toll-free call center to answer questions about the incident and to address related concerns. Call center representatives are available Monday through Friday between 6:00 am – 6:00 pm Pacific Time and can be reached at 1-833-764-2924. Individuals can also access information regarding the incident, services, and steps you can take to protect your information online at https://response.idx.us/SDAIHC. All potentially affected individuals may qualify for complimentary credit monitoring and identity protection services through IDX.  Individuals who have not received a notification letter must obtain verification of eligibility through the call center to enroll in services.

The privacy and protection of personal and protected health information is a top priority for SDAIHC, which deeply regrets any inconvenience or concern this incident may cause.

While we are not aware of the misuse of any potentially affected individual’s information, we are providing the following information to help those who want to know more about steps they can take to protect themselves and their personal information:

What steps can I take to protect my personal information?

  • Please notify your financial institution immediately if you detect any suspicious activity on any of your accounts, including unauthorized transactions or new accounts opened in our name that you do not recognize. You should also promptly report any fraudulent activity or any suspected incidents of identity theft to proper law enforcement authorities.
  • You can request a copy of your credit report, free of charge, directly from each of the three nationwide credit reporting agencies. To do so, free of charge once every 12 months, please visit www.annualcreditreport.com or call toll free at 1-833-365-2599. Contact information for the three nationwide credit reporting agencies is listed at the bottom of this page.
  • You can take steps recommended by the Federal Trade Commission to protect yourself from identify theft. The FTC’s website offers helpful information at ftc.gov/idtheft.
  • Additional information on what you can do to better protect yourself is included in your notification letter.

How do I obtain a copy of my credit report?

You can obtain a copy of your credit report, free of charge, directly from each of the three nationwide credit reporting agencies.  To order your credit report, free of charge once every 12 months, please visit www.annualcreditreport.com or call toll free at 1-877-322-8228. Use the following contact information for the three nationwide credit reporting agencies:

TransUnion

P.O. Box 1000

Chester, PA 19016

1-800-916-8800

www.transunion.com

Experian

P.O. Box 9532

Allen, TX 75013

1-888-397-3742

www.experian.com

Equifax

P.O. Box 105851

Atlanta, GA 30348

1-800-685-1111

www.equifax.com

How do I put a fraud alert on my account?

You may consider placing a fraud alert on your credit report. This fraud alert statement informs creditors to possible fraudulent activity within your report and requests that your creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact Equifax, Experian or TransUnion and follow the Fraud Victims instructions. To place a fraud alert on your credit accounts, contact your financial institution or credit provider. Contact information for the three nationwide credit reporting agencies is included in the letter and is also listed at the bottom of this page.

How do I put a security freeze on my credit reports?

You also have the right to place a security freeze on your credit report. A security freeze is intended to prevent credit, loans and services from being approved in your name without your consent. To place a security freeze on your credit report, you need to make a request to each consumer reporting agency. You may make that request by certified mail, overnight mail, or regular stamped mail, or online by following the instructions found at the websites listed below. You will need to provide the following information when requesting a security freeze (note that if you are making a request for your spouse, this information must be provided for him/her as well): (1) full name, with middle initial and any suffixes; (2) Social Security number; (3) date of birth; (4) address. You may also be asked to provide other personal information such as your email address, a copy of a government-issued identification card, and  a copy of a recent utility bill or bank or insurance statement. It is essential that each copy be legible, display your name and current mailing address, and the date of issue. There is no charge to place, lift, or remove a freeze. You may obtain a security freeze by contacting any one or more of the following national consumer reporting agencies:

Equifax Security Freeze
PO Box 105788
Atlanta, GA 30348
1-800-685-1111
www.equifax.com
Experian Security Freeze
PO Box 9701
Allen, TX 75013
1-888-397-3742
www.experian.com
TransUnion (FVAD)
PO Box 2000
Chester, PA 19022
1-800-909-8872
www.transunion.com

What should I do if my family member was involved in the incident and is deceased?

You may choose to notify the three major credit bureaus, Equifax, Experian and Trans Union, and request they flag the deceased credit file. This will prevent the credit file information from being used to open credit. To make this request, mail a copy of your family member’s death certificate to each company at the addresses below.

Equifax

Equifax Information Services

P.O. Box 105169

Atlanta, GA 30348

Experian

Experian Information Services

P.O. Box 9701

Allen, TX 75013

TransUnion

Trans Union Information Services

P.O. Box 2000

Chester, PA 19022

What should I do if my minor child or protected person’s information was involved in the incident?

You can request that each of the three national credit reporting agencies perform a manual search for a minor’s or protected person’s Social Security number to determine if there is an associated credit report. Copies of identifying information for the minor and parent/guardian may be required, including birth or adoption certificate, Social Security card and government issued identification card. If a credit report exists, you should request a copy of the report and immediately report any fraudulent accounts to the credit reporting agency. You can also report any misuse of a minor’s information to the FTC at https://www.identitytheft.gov/. For more information about Child Identity Theft and instructions for requesting a manual Social Security number search, visit the FTC website:

https://www.consumer.ftc.gov/articles/0040-child-identity-theft. Contact information for the three national credit reporting agencies may be found above.