DisclosureLens
MalwareTechnologyHealthcareInformationRansomwareData EncryptedData ExfiltratedTargetedIdentity (basic)Government IDHealth (basic)Financial accountCredentialsAuthenticationMediumContained

PracticeMax

bd_1177178985ed0fab · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 1, 2021

Filed

Mar 4, 2022

To disclose

44 weeks

Affected

145state residents only

Linked

5 filings

Confidence

65%
Full breach record for PracticeMax6 incidents on file

PracticeMax, a business management and IT solutions provider, disclosed a ransomware incident where unauthorized access occurred from April 17 to May 5, 2021. The attack encrypted data and potentially exfiltrated sensitive information including SSNs, health data, and credentials. PracticeMax detected the incident on May 1, 2021, engaged forensic specialists, notified the FBI and regulators, and began notifying affected individuals in October 2021.

Incident timeline

undetected · 14 days
discovery → filing · 44 weeks / 307 days

Apr 17, 2021

Begins

May 1, 2021

Discovered

Mar 4, 2022

Filed

vs. sector median

+25 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Maine State AGMar 4 · first
Indiana State AGMar 4 · first
Montana State AGMar 4 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.