HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (Dependency)PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Data Media Associates
bd_44951a0ed5c0c1c7 · schema v1 · pii pii-v1
Full breach record for Data Media Associates →Data Media Associates, LLC disclosed a data breach affecting protected health information due to the exploitation of a critical vulnerability in MOVEit Transfer software. The incident occurred between May 31 and June 1, 2023, and was discovered in June 2023. Affected data may include names, addresses, health insurance IDs (potentially SSNs), and other PHI. The company patched the system, engaged external experts, and offered identity theft protection services.
California clockDiscovered Jun 1, 2023 → Notified Aug 23, 202383d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_b6d2939432620ba9Delaware State AGfiled 2023-08-23Verified
- bd_f47ab4ae0c5fc070Maine State AGfiled 2023-08-23Verified
- bd_5fe69a1c32fcae1bWashington State AGfiled 2023-09-25(33d gap)Verified
- bd_dd8d071e11b9229bMaine State AGfiled 2023-09-25(33d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 47d gap
- bd_54c0ed94f9613269HHS OCRfiled 2023-10-09(47d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572311
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- b973db519d6cd226cb1f7576862ec1a9b6f514cc5c3775d08f209a35c3b861e5
Reporting entity
- Name
- Data Media Associatesnorm: data media associates
Victim entity
- Name
- Data Media Associatesnorm: data media associates
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 23, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- CA 60-day late · 83d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2023→ Notified: Aug 23, 202383d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.