HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Three Rivers Provider Network
bd_1135fa5e115212d4 · schema v1 · pii pii-v1
Full breach record for Three Rivers Provider Network →Three Rivers Provider Network identified unauthorized access to an employee email account on June 3, 2022. The breach, which occurred on June 2, 2022, potentially exposed personal information including names, addresses, SSNs, and protected health information (PHI) such as treatment and diagnosis data. The company secured the account and is offering credit monitoring.
California clockDiscovered Jun 3, 2022 → Notified Oct 15, 2022134d ✗ CA 60-day late14 months discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_462f0f4c5aee53c8Maine State AGfiled 2023-07-21Verified
- bd_b43d57a3b1062d1dNew Hampshire State AGfiled 2023-07-28(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570682
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- e66ec3d74ff5234c9ec18d7558f96eb2184b1c72f71b25fdcdb596654a15e464
Reporting entity
- Name
- Three Rivers Provider Networknorm: three rivers provider network
Victim entity
- Name
- Three Rivers Provider Networknorm: three rivers provider network
Incident
- Discovered
- Jun 3, 2022
- Materiality determined
- —
- Notification sent
- Oct 15, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(413 days from discovery to filing)
- Compliance flags
- CA 60-day late · 134d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 3, 2022→ Notified: Oct 15, 2022134d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.