DisclosureLens
HackingProfessional ServicesProfessional ServicesVulnerability ExploitTargetedData ExfiltratedFinancial accountIdentity (basic)LowContained

American Society for Clinical Pathology

bd_1c56d6fdb347f291 · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 11, 2021

Filed

Apr 12, 2021

To disclose

5 weeks

Affected

138state residents only

Linked

8 filings

Confidence

66%
Full breach record for American Society for Clinical Pathology

ASCP notified NH AG of a cybersecurity attack on its e-commerce website exposing payment card data (names, card numbers, CVVs) for ~138 NH residents. Attack occurred between March 30 and Nov 6, 2020. ASCP engaged forensic investigators, resolved the issue, and implemented additional security safeguards. No evidence of misuse found.

Incident timeline

undetected · 346 days
discovery → filing · 5 weeks / 32 days

Mar 30, 2020

Begins

Mar 11, 2021

Discovered

Apr 12, 2021

Filed

vs. sector median

13 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 29d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗
Montana State AGApr 1 · first
Indiana State AGApr 1 · first
New Hampshire State AG+11d · this page

Pattern: first filing Apr 1 (MT), last May 11 (OR) — a 40-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.