American Society for Clinical Pathology
bd_1c56d6fdb347f291 · schema v1 · pii pii-v1
Full breach record for American Society for Clinical Pathology →ASCP notified NH AG of a cybersecurity attack on its e-commerce website exposing payment card data (names, card numbers, CVVs) for ~138 NH residents. Attack occurred between March 30 and Nov 6, 2020. ASCP engaged forensic investigators, resolved the issue, and implemented additional security safeguards. No evidence of misuse found.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 30, 2020
Begins
Mar 11, 2021
Discovered
Apr 12, 2021
Filed
vs. sector median
13 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Washington State AGbd_0068d4a7a36ff7b72021-04-07 · +5dVerified by operator
- California State AGbd_50dbb9c8e5101fcf2021-04-07 · +5dVerified
- Massachusetts State AGbd_ae4d677d9170ca6d2021-04-07 · +5dVerified
- Maine State AGbd_cb2b3e87c8a69a2e2021-04-07 · +5dVerified by operator
Show 3 more filings ↓Show fewer ↑up to 29d gap
- Montana State AGbd_2e4a4fe0820ab0af2021-04-01 · +11dCandidate
- Indiana State AGbd_8246d19f98183f762021-04-01 · +11dVerified
- Oregon State AGbd_1a1b74d201b159d82021-05-11 · +29dVerified by operator
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Apr 1 (MT), last May 11 (OR) — a 40-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.