MalwareRansomwareData ExfiltratedRansom DemandedCustomer Data InvolvedEmployee Data InvolvedPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Affiliated Dermatologists and Dermatologic Surgeons PA
bd_5702f907d3465133 · schema v1 · pii pii-v1
Full breach record for Affiliated Dermatologists and Dermatologic Surgeons PA →Affiliated Dermatologists & Dermatologic Surgeons P.A. experienced a ransomware attack between March 2 and March 5, 2024. An unauthorized third party gained access to the network, left a ransom note, and copied data including personal information of patients and employees. The incident was detected on March 5, 2024. The organization disconnected the network, engaged forensic investigators, and implemented enhanced security measures including 24/7 monitoring and MFA. Credit monitoring services were offered to affected individuals.
California clockDiscovered Mar 5, 2024 → Notified May 23, 202479d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_4a47b006cd35e002Leak Sitebianlianfiled 2024-03-26(57d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_0ea78c864d79336eMontana State AGfiled 2024-05-23Verified
- bd_e383e7d553cc2a01Vermont State AGfiled 2024-05-23Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585886
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2024
- Raw hash
- b3e41340f8fe3ec347f49cca432cc4d3843383f54b585b7cb9a29148095d7456
Reporting entity
- Name
- Affiliated Dermatologists and Dermatologic Surgeons PAnorm: affiliated dermatologists and dermatologic surgeons
- Domain
- affiliateddermatologists.com
Victim entity
- Name
- Affiliated Dermatologists and Dermatologic Surgeons PAnorm: affiliated dermatologists and dermatologic surgeons
- Domain
- affiliateddermatologists.com
Incident
- Discovered
- Mar 5, 2024
- Materiality determined
- —
- Notification sent
- May 23, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day late · 79dLeak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 5, 2024→ Notified: May 23, 202479d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.