OnePoint Patient Care
bd_3f7e05d630c49768 · schema v1 · pii pii-v1
Full breach record for OnePoint Patient Care →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
One Point Patient Care (OPPC) founded in 1965 and headquartered in Tempe, Arizona, is a national, hospice-focused pharmacy providing delivery, mail-order and Pharmacy Benefit Management (PBM) all under one service umbrella.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 12, 2024
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Massachusetts State AGbd_550d50e896eee6832024-10-23 · +40dVerified by operator
- Oregon State AGbd_576ce027515e48962024-10-23 · +40dVerified
- Washington State AGbd_a2930aeb690067af2024-10-23 · +40dCandidate
- Oregon State AGbd_a04fe40ab837a1512024-11-22 · +70dVerified
Show 6 more filings ↓Show fewer ↑up to 146d gap
- California State AGbd_b80758011a6c84382024-11-22 · +70dVerified
- Maine State AGbd_e783d73da1f1cb112024-11-22 · +70dVerified
- South Carolina State AGbd_1ee37ad8137f49dd2024-11-25 · +73dVerified
- New Hampshire State AGbd_b99dbbb3e344646d2024-11-25 · +73dVerified
- California State AGbd_8adcaa2abc34f2c02025-02-06 · +146dVerified
- Oregon State AGbd_f55bcb1e60892a2a2025-02-06 · +146dVerified
Showing first 10 of 15 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Sep 12, last Feb 6 (OR) — a 146-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 15 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.