HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Watsonville Chiropractic, Inc.
bd_4a370167f1b2f480 · schema v1 · pii pii-v1
Full breach record for Watsonville Chiropractic, Inc. →Watsonville Chiropractic, Inc. reported a data breach involving its billing software provider's Amazon S3 storage account. The account was vulnerable and accessible to unauthorized parties from May 2016 to September 11, 2016. A security researcher accessed and downloaded patient data, including names, addresses, SSNs, and protected health information. The provider secured the account, and the researcher deleted the data. Watsonville notified affected individuals and regulators, offering credit monitoring via Equifax.
California clockDiscovered Sep 11, 2016 → Notified Nov 15, 201665d ✗ CA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5ffc056147ab8dccHHS OCRfiled 2016-11-17Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64960
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2016
- Raw hash
- dace405b7f7d445eaeda26a6d6495c135e0a72d992d158a03d587e7b3f2ba2a8
Reporting entity
- Name
- Watsonville Chiropractic, Inc.norm: watsonville chiropractic
Victim entity
- Name
- Watsonville Chiropractic, Inc.norm: watsonville chiropractic
Incident
- Discovered
- Sep 11, 2016
- Materiality determined
- —
- Notification sent
- Nov 15, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1530 Data from Cloud Storage Object
- Threat actor
- External
- Regulator citations
- Provided notice of this incident to certain state regulators and the Department of Health and Human Services
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- CA 60-day late · 65d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 11, 2016→ Notified: Nov 15, 201665d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.