CoPilot Provider Support Services
bd_3fcbaac7d52604cb · schema v1 · pii pii-v1
Full breach record for CoPilot Provider Support Services →CoPilot Provider Support Services, Inc. experienced unauthorized access to its database via a website used by physicians to check insurance coverage for ORTHOVISC and MONOVISC injections. The incident occurred in October 2015 and was discovered on December 23, 2015. An individual accessed the database through unauthorized means and downloaded health information, including names, dates of birth, addresses, phone numbers, and medical insurance card information. One version of the notice indicated Social Security numbers were not involved, while another indicated they were. CoPilot engaged a cybersecurity firm, referred the matter to law enforcement, and offered one year of identity monitoring through Kroll.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_e59a4c6a95b27063Oregon State AGfiled 2017-01-19Verified
- bd_1124dc30d1055ed7Montana State AGfiled 2017-01-18(1d gap)Candidate
- bd_1c6e96eda7cdcd68Washington State AGfiled 2017-01-18(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65922
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2017
- Raw hash
- 8ead02d8b1da3440ae43694d6ce5acabc7c30d97a2d794062151213087384ba5
Reporting entity
- Name
- CoPilot Provider Support Servicesnorm: copilot provider support
Victim entity
- Name
- CoPilot Provider Support Servicesnorm: copilot provider support
Incident
- Discovered
- Dec 23, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 13 months(393 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.