HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Sunrise Medical Laboratories
bd_59cde26408fd9d4f · schema v1 · pii pii-v1
Full breach record for Sunrise Medical Laboratories →Sunrise Medical Laboratories, Inc. notified California regulators of a data security incident involving its third-party vendor, Retrieval Masters Creditors Bureau (d/b/a American Medical Collection Agency). The vendor's website payment page and database were compromised, potentially exposing patient names, addresses, dates of birth, and treatment information. Sunrise engaged cybersecurity experts, terminated the vendor relationship, and sent notification letters to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148939
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2019
- Raw hash
- 93c68116acdc599397139fcf245712aa848cf465ef0306a71aaf79d4035ee219
Reporting entity
- Name
- Sunrise Medical Laboratoriesnorm: sunrise medical laboratories
Victim entity
- Name
- Sunrise Medical Laboratoriesnorm: sunrise medical laboratories
Incident
- Discovered
- May 15, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Retrieval Masters Creditors Bureau d/b/a American Medical Collection Agency
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.