AccidentalMisconfigurationData ExfiltratedCustomer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Altos Inc
bd_3f372da7fd54a53e · schema v1 · pii pii-v1
Full breach record for Altos Inc →Altos, a billing services provider for healthcare providers in southern California, experienced a data breach due to an internal system exposed to the Internet. The incident occurred between May 30 and May 31, 2025, and was discovered on June 17, 2025. An unauthorized third party accessed the system and may have exfiltrated personal and health information, including names, addresses, dates of birth, Social Security numbers, and health information. Altos blocked access to the system, hired a cybersecurity firm, and is offering credit monitoring to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_de689aaa60106cebIndiana State AGfiled 2025-08-01Verified
- bd_062a49a15a817d37HHS OCRfiled 2025-08-11(10d gap)Verified
- bd_56b1f270267296a0HHS OCRfiled 2025-08-11(10d gap)Verified
- bd_60b51f79707513f4HHS OCRfiled 2025-08-11(10d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 10d gap
- bd_92a4b394745af1bdHHS OCRfiled 2025-08-11(10d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606489
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2025
- Raw hash
- 0fa25ab194bfb202402690357ef921091fdc658813da84ca686fac098ad34810
Reporting entity
- Name
- Altos Incnorm: altos
Victim entity
- Name
- Altos Incnorm: altos
Incident
- Discovered
- Jun 17, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.