HackingData MishandlingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICHEALTH_BASICPHIFINANCIAL_ACCOUNTLowContained
U.S.Vision, Inc.,
bd_40755fd7d00dcd24 · schema v1 · pii pii-v1
Full breach record for U.S.Vision, Inc., →U.S. Vision, Inc. reported that an unauthorized individual accessed its network between April 20 and May 17, 2021, with discovery occurring on May 12, 2021. The incident potentially exposed personal identifying information, vision care/treatment records (PHI), insurance information, and billing data. The company engaged third-party cybersecurity specialists, conducted a comprehensive file review, and assessed system security. No specific malware or threat actor was identified.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_6dd0d0cf51cb59a5Washington State AGfiled 2024-03-20(1d gap)Verified
- bd_9e4a698e2832d914Oregon State AGfiled 2024-03-20(1d gap)Verified
- bd_e39c5fc00cafebbaCalifornia State AGfiled 2022-11-30(475d gap)Verified
- bd_3a70be4ee1cba8bcCalifornia State AGfiled 2022-10-28(508d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 928d gap
- bd_e91a5ca72815c0ddCalifornia State AGfiled 2022-10-28(508d gap)Verified
- bd_8895c6bff85665b8Delaware State AGfiled 2021-09-03(928d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582677
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2024
- Raw hash
- 10141e3815ef62372f51341bbd09e96a394c6c6fff2712ae436c447e6d017d0e
Reporting entity
- Name
- U.S.Vision, Inc.,norm: usvision
Victim entity
- Name
- U.S.Vision, Inc.,norm: usvision
Incident
- Discovered
- May 12, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 35 months(1042 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.