HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Berry, Dunn, McNeil & Parker, LLC
bd_4520bec96d46671d · schema v1 · pii pii-v1
Full breach record for Berry, Dunn, McNeil & Parker, LLC →Berry, Dunn, McNeil & Parker, LLC notified California residents of a data security incident involving its vendor, Health Analytics Practice Group (HAPG), and HAPG's managed service provider, Reliable Networks of Maine, LLC. An unauthorized actor gained access to Reliable's network between September 12 and September 14, 2023, and exfiltrated data from HAPG systems. Affected data may include names and addresses. BerryDunn engaged cybersecurity experts, decommissioned affected systems, and is offering identity theft protection.
California clockDiscovered Sep 14, 2023 → Notified Apr 11, 2024210d ✗ CA 60-day late32 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_14408f93c96da4c4Indiana State AGfiled 2024-04-25Verified
- bd_35abf7fd26ee26d0Maine State AGfiled 2024-04-25Candidate
- bd_575174f141af5da6Montana State AGfiled 2024-04-25Verified by operator
- bd_72b772a3d97ca5ddOregon State AGfiled 2024-04-25Candidate
Show 1 more filing ↓Show fewer ↑
- bd_e4ba1a5134b4067eWashington State AGfiled 2024-04-25Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-584457
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2024
- Raw hash
- 800bac6f3631e434f8ee09feb08146704226dc11be14b28900ef297189218fbe
Reporting entity
- Name
- Berry, Dunn, McNeil & Parker, LLCnorm: berry dunn mcneil parker
Victim entity
- Name
- Berry, Dunn, McNeil & Parker, LLCnorm: berry dunn mcneil parker
Incident
- Discovered
- Sep 14, 2023
- Materiality determined
- —
- Notification sent
- Apr 11, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Reliable Networks of Maine, LLC
- Initial access
- supply_chain
Compliance
- Time to disclose
- 32 weeks(224 days from discovery to filing)
- Compliance flags
- CA 60-day late · 210d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 14, 2023→ Notified: Apr 11, 2024210d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.