HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMINORMediumContained
Cardiovascular Associates Holdings, LP
bd_3101fb359642d7d3 · schema v1 · pii pii-v1
Full breach record for Cardiovascular Associates Holdings, LP →Cardiovascular Associates disclosed an unauthorized access incident affecting patient data in Alabama. An external actor accessed systems between Nov 28 and Dec 5, 2022, exfiltrating PHI, PII, and financial data. The breach was discovered on Dec 5, 2022. Forensic investigation was engaged, and identity monitoring was offered to affected individuals.
California clockDiscovered Dec 5, 2022 → Notified Feb 3, 202360d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_489906bb2eebc73fVermont State AGfiled 2023-02-03Verified
- bd_bfd43f9919ac6f72Montana State AGfiled 2023-02-03Verified
- bd_cd85f8eca6803424New Hampshire State AGfiled 2023-02-06(3d gap)Verified
- bd_1e18382a04b09a26California State AGfiled 2023-03-17(42d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 42d gap
- bd_c613160ae6c07cfdMaine State AGfiled 2023-03-17(42d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-562686
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 3, 2023
- Raw hash
- c909e0414d0fd44c902267c4846a49912711a529784009082f88fde427cc131c
Reporting entity
- Name
- Cardiovascular Associates Holdings, LPnorm: cardiovascular associates
Victim entity
- Name
- Cardiovascular Associates Holdings, LPnorm: cardiovascular associates
Incident
- Discovered
- Dec 5, 2022
- Materiality determined
- —
- Notification sent
- Feb 3, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 5, 2022→ Notified: Feb 3, 202360d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.