DisclosureLens
HackingHealthcareHealthcareCustomer Data InvolvedBusiness Associate (HIPAA)Identity (basic)PHIHealth (basic)LowContained

Eisner Health

bd_433c5fc9771c6681 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 22, 2022

Filed

May 26, 2023

To disclose

22 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Eisner Health

Nonstop Administration and Insurance Services, Inc., a business associate of Eisner Health, notified the California Attorney General of an unauthorized access incident. On December 22, 2022, an unknown party accessed a cloud services platform maintained by Nonstop. The investigation determined that the access was unauthorized and occurred for a limited time. The data involved included names and other health-related information. Nonstop engaged forensic specialists, reported the incident to law enforcement, and implemented a redesigned cloud-services workflow. Affected individuals were offered credit monitoring and identity protection services.

California clockDiscovered Dec 22, 2022Notified Feb 15, 202355d CA 60-day OK22 weeks discovery → filing

Incident timeline

discovery → filing · 22 weeks / 155 days

Dec 22, 2022

Begins

Dec 22, 2022

Discovered

May 26, 2023

Filed

vs. sector median

+10 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.