MalwareRansomwareData EncryptedCustomer Data InvolvedBusiness Associate (HIPAA)PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Reventics
bd_1c7e9cb573ae65b0 · schema v1 · pii pii-v1
Full breach record for Reventics →Reventics, LLC, a revenue cycle management company, detected a cyber-intruder who encrypted and potentially accessed information on its servers on December 15, 2022. The incident involved the unauthorized acquisition of PII and PHI, including names, SSNs, medical record numbers, and clinical data. Reventics engaged forensic consultants, contained the threat, and is offering identity protection services to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_444910ac807ff50eMontana State AGfiled 2023-02-10(14d gap)Verified
- bd_e4bccaf0084682c8HHS OCRfiled 2023-02-10(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563598
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2023
- Raw hash
- 6303f75c3adc0ea51dd9d718fe9ecb84d24d7b62dca582724cf9d13d2a568dc4
Reporting entity
- Name
- Reventicsnorm: reventics
- Domain
- reventics.com
Victim entity
- Name
- Reventicsnorm: reventics
- Domain
- reventics.com
Incident
- Discovered
- Dec 15, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.