HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPHIHEALTH_BASICIDENTITY_GOVERNMENTMediumContained
USACS Management Group, Ltd.
bd_1b6305722a9ae92a · schema v1 · pii pii-v1
Full breach record for USACS Management Group, Ltd. →USACS Management Group, Ltd. disclosed that an unauthorized third party may have accessed an employee's email account on March 9, 2018. The compromised email may have contained patient information including names, addresses, dates of service, account numbers, medical and health insurance information, diagnostic and treatment information, and Social Security numbers. USACS engaged a forensic firm and offered one year of identity monitoring services to affected individuals.
California clockDiscovered Mar 9, 2018 → Notified May 8, 201860d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_28f5dd93d1928bcdHHS OCRfiled 2018-05-08Verified
- bd_ec23e2aaf77d1b4cMontana State AGfiled 2018-05-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135980
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2018
- Raw hash
- 11c79279cff3e13d69849f65ef9217e09e180d4333dc1b91fddc5760f78a373c
Reporting entity
- Name
- USACS Management Group, Ltd.norm: usacs management
Victim entity
- Name
- USACS Management Group, Ltd.norm: usacs management
Incident
- Discovered
- Mar 9, 2018
- Materiality determined
- —
- Notification sent
- May 8, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 9, 2018→ Notified: May 8, 201860d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.