California Massage Therapy Council
bd_1e06efde36f08fc9 · schema v1 · pii pii-v1
Full breach record for California Massage Therapy Council →California Massage Therapy Council notified the California Attorney General of a potential data security incident. The organization learned of the incident on February 22, 2021, involving a payment page breach that occurred on November 4, 2020. The incident potentially impacted names, addresses, payment card numbers, expiration dates, and security codes. An investigation found no evidence of compromise, but notification was sent out of an abundance of caution. The payment page was migrated to a new platform with enhanced security.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 4, 2020
Begins
Feb 22, 2021
Discovered
Sep 8, 2021
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_886e13f1c8d271542021-09-08Verified
- Maine State AGbd_9c5fa93deaaab8502021-09-08Candidate
- Indiana State AGbd_8ea8769fa0759df22021-08-26 · +13dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Aug 26 (IN), last Sep 8 (CA) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.