HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)PIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Orrick, Herrington & Sutcliffe LLP
bd_3fe3320cbc86fe1b · schema v1 · pii pii-v1
Full breach record for Orrick, Herrington & Sutcliffe LLP →Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick is a downstream service provider for MultiPlan, Inc. The firm engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring through Kroll.
California clockDiscovered Mar 13, 2023 → Notified Jun 1, 202380d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 13 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_2219323be28eb8d7Oregon State AGfiled 2023-08-18(4d gap)Verified
- bd_cc48c408ae3ef894Maine State AGfiled 2023-08-18(4d gap)Verified
- bd_13c2d48c6c504f77California State AGfiled 2023-08-21(7d gap)Verified
- bd_cbf3d3e27848f13eCalifornia State AGfiled 2023-07-31(14d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 45d gap
- bd_d10cdbb5d734268cMaine State AGfiled 2023-07-20(25d gap)Verified
- bd_e91b9e52ec6efee0Maine State AGfiled 2023-07-20(25d gap)Verified
- bd_eb15c77ac453f478California State AGfiled 2023-07-20(25d gap)Verified
- bd_4e6e3b6b46e7862bNew Hampshire State AGfiled 2023-07-03(42d gap)Verified
- bd_47f8b56acf0704e4Oregon State AGfiled 2023-06-30(45d gap)Verified
- bd_6acd93d28371c8a0Washington State AGfiled 2023-06-30(45d gap)Verified
Showing first 10 of 12 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571820
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- 0d719f07fd3069972bcc2bfd7df600c044bb11b9e53b3cb6ae77317d41a266a6
Reporting entity
- Name
- Orrick, Herrington & Sutcliffe LLPnorm: orrick herrington sutcliffe
- Domain
- orrick.com
Victim entity
- Name
- Orrick, Herrington & Sutcliffe LLPnorm: orrick herrington sutcliffe
- Domain
- orrick.com
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- Jun 1, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified the health insurance plan in which you are or were enrolled
- Third party
- via MultiPlan, Inc.
Compliance
- Time to disclose
- 22 weeks(154 days from discovery to filing)
- Compliance flags
- CA 60-day late · 80d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 13, 2023→ Notified: Jun 1, 202380d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.