MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryMulti-Stage ChainTargetedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCriticalContained
PracticeMax
bd_3bbfba4a3095fb69 · schema v1 · pii pii-v1
Full breach record for PracticeMax →PracticeMax, a healthcare technology provider, disclosed a ransomware attack on April 17, 2021, affecting approximately 165,698 individuals. The incident involved the Medusa ransomware family, which encrypted patient data on a server and resulted in the exfiltration of sensitive information including names, Social Security numbers, and health records. Notifications were sent to the FBI, HHS, and affected individuals starting in October 2021, with written notices continuing through June 2022.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_41650c90bc215032Maine State AGfiled 2022-06-10Verified
- bd_c3ddc5b7d5967e6fCalifornia State AGfiled 2022-06-10Candidate
- bd_f61da3d5b25643d6Oregon State AGfiled 2022-06-10Verified
- bd_63b71b27f7b47bdfNew Hampshire State AGfiled 2022-06-14(4d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2022/PracticeMax.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2022
- Raw hash
- c27b33c98068ec1b7c9705d3f658d6c404c30160bbc01887b3f05b2988ba1742
Reporting entity
- Name
- PracticeMaxnorm: practicemax
- Domain
- practicemax.com
Victim entity
- Name
- PracticeMaxnorm: practicemax
- Domain
- practicemax.com
Incident
- Discovered
- Apr 17, 2021
- Materiality determined
- Jun 10, 2022
- Notification sent
- Jun 10, 2022
- Affected individuals
- 165,698
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 months(419 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.