Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
NCP Healthcare Management Company
bd_08b52b7dfc46da80 · schema v1 · pii pii-v1
Full breach record for NCP Healthcare Management Company →NCP Healthcare Management Company reported a cybersecurity incident on July 17, 2020, affecting California residents. On April 27, 2020, an unauthorized individual gained access to an employee's email account via phishing. NCP discovered the breach on May 19, 2020, terminated access, and engaged forensic investigators. The incident involved the potential exposure of patient/provider names and addresses. No evidence of actual viewing or misuse was found. NCP offered one year of Experian IdentityWorks monitoring to affected individuals.
California clockDiscovered May 19, 2020 → Notified Jul 17, 202059d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0916ec6a0bc81cbcHHS OCRfiled 2020-07-17Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-192132
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2020
- Raw hash
- 1250fd74b9dc243d0d5abe532f95d865e0e06d217a8b477b30dc5e397f2430fd
Reporting entity
- Name
- NCP Healthcare Management Companynorm: ncp healthcare management
Victim entity
- Name
- NCP Healthcare Management Companynorm: ncp healthcare management
Incident
- Discovered
- May 19, 2020
- Materiality determined
- —
- Notification sent
- Jul 17, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 19, 2020→ Notified: Jul 17, 202059d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.