HackingHealthcareHealthcareExtortion DemandCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedRansom DemandedRansom PaidCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTEMPLOYMENTMediumContained
Harvard Eye Associates
bd_3bdb3e6c2815d1d0 · schema v1 · pii pii-v1
Full breach record for Harvard Eye Associates →Harvard Eye Associates notified patients and employees of a data breach involving a third-party online data storage vendor. Hackers accessed the vendor's system as early as October 24, 2020; the vendor discovered the intrusion and notified Harvard Eye on January 15, 2021. The hackers demanded ransom; the vendor paid and the data was returned. Compromised data included patient PHI, employee PII (SSNs, bank account numbers, government IDs), and affiliated individuals' information. IDX identity protection services were offered.
California clockDiscovered Jan 15, 2021 → Notified Feb 5, 202121d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_36fb89cb0ceb607eHHS OCRfiled 2021-02-08(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538038
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 16, 2021
- Raw hash
- ff9c23f367e39f9167d35956a6b5fd74435db2176a2bf371cd2a7eae9448bbeb
Reporting entity
- Name
- Harvard Eye Associatesnorm: harvard eye associates
Victim entity
- Name
- Harvard Eye Associatesnorm: harvard eye associates
- Industry
- Healthcarellm
Incident
- Discovered
- Jan 15, 2021
- Materiality determined
- —
- Notification sent
- Feb 5, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney GeneralVendor notified the FBI
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 15, 2021→ Notified: Feb 5, 202121d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.