HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Utah Imaging Associates, Inc.
bd_38ab113f98078b4b · schema v1 · pii pii-v1
Full breach record for Utah Imaging Associates, Inc. →Utah Imaging Associates, Inc. notified patients of a data security incident detected on September 4, 2021. Unauthorized access to sensitive patient data, including names, SSNs, DOBs, and medical information, occurred between August 29 and September 4, 2021. The company engaged forensic investigators, secured its network, and offered credit monitoring services. No identity theft has been reported.
California clockDiscovered Sep 4, 2021 → Notified Nov 18, 202175d ✗ CA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_a12cdd64505a29d6Oregon State AGfiled 2021-11-18Candidate
- bd_b921bf4c6e655761Montana State AGfiled 2021-11-18Verified
- bd_b99f93283499ea10Maine State AGfiled 2021-11-18Candidate
- bd_cc7b033a3b6ae541Washington State AGfiled 2021-11-18Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547748
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2021
- Raw hash
- e6ba8e1fd9c2d36a7c9485d3eb9580287d5c933b473fe3f076e218feefc16bbf
Reporting entity
- Name
- Utah Imaging Associates, Inc.norm: utah imaging associates
Victim entity
- Name
- Utah Imaging Associates, Inc.norm: utah imaging associates
Incident
- Discovered
- Sep 4, 2021
- Materiality determined
- —
- Notification sent
- Nov 18, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- CA 60-day late · 75d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 4, 2021→ Notified: Nov 18, 202175d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.