HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Clinivate LLC
bd_4ae5d95e4372bb17 · schema v1 · pii pii-v1
Full breach record for Clinivate LLC →Clinivate, LLC, an electronic health records vendor, disclosed a data breach affecting patient and employee information. Unauthorized access occurred between March 12 and March 21, 2022, discovered on March 23, 2022. Affected data included names, SSNs, medical record numbers, diagnosis/treatment info, and payment details. Clinivate engaged forensic investigators, notified the FBI, and offered complimentary identity monitoring services to affected individuals.
California clockDiscovered Mar 23, 2022 → Notified Jul 22, 2022121d ✗ CA 60-day late17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f54c2d091ffb6bdeMontana State AGfiled 2022-07-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555528
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2022
- Raw hash
- c965cd48bf3c465530a5cb183a1309ad949881199c60890b424da4337459cdb0
Reporting entity
- Name
- Clinivate LLCnorm: clinivate
Victim entity
- Name
- Clinivate LLCnorm: clinivate
Incident
- Discovered
- Mar 23, 2022
- Materiality determined
- —
- Notification sent
- Jul 22, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- CA 60-day late · 121d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 23, 2022→ Notified: Jul 22, 2022121d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.