
Several California healthcare organizations started sending security breach notifications to more than three million patients alerting them that cyber criminals may have stolen their sensitive personal information during a ransomware attack on December 1, 2022.
The organizations include Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, and Greater Covina Medical. The stolen patients’ information includes names, dates of birth, social security numbers, addresses, diagnosis and treatment information, phone numbers, laboratory test results, prescription data, radiology reports, and health plan member numbers.
The US Department of Health and Human Services, which is currently investigating the breach, said the attack affected 3,300,638 people.
According to a notice released by Regal, the malware was detected on some of the servers, which a threat actor used to access and exfiltrate data. The organization hired third-party incident responders and collaborated with security vendors to re-establish access to its systems and determine what data was affected.
Regal is taking steps to notify potentially affected individuals of this breach to ensure transparency, according to the company’s notification, which also stated that the ransomware attack was reported to law enforcement and regulatory agencies. Regal did not disclose who was responsible for the attack, how they gained entry, how much money the attackers demanded, and whether the health network paid the ransom.
The medical groups stated they would pay for one year of Norton LifeLock credit monitoring for affected customers. They also advised patients to set up a fraud alert with various credit bureaus and to closely monitor account statements and benefit explanation forms.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543