HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Lincare Holdings Inc.
bd_5b9e74ab50bbbb51 · schema v1 · pii pii-v1
Full breach record for Lincare Holdings Inc. →Lincare Holdings Inc. reported a security incident to the California Attorney General's Office. Unauthorized access occurred between September 10 and September 29, 2021. The breach involved the disclosure of personal information, including names and government identifiers. Lincare engaged outside cybersecurity experts, notified law enforcement, reset passwords, and offered one year of complimentary credit monitoring through Kroll. The incident status is contained.
California clockDiscovered Sep 26, 2021 → Notified Apr 20, 2022206d ✗ CA 60-day late36 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_133c1a54ff8a079fOregon State AGfiled 2022-06-06Verified by operator
- bd_36323b1248fdb686Oregon State AGfiled 2022-04-11(56d gap)Verified by operator
- bd_c6e8a20ea78d5a7bWashington State AGfiled 2022-03-25(73d gap)Verified by operator
- bd_54f6545e86d1e397Montana State AGfiled 2022-02-09(117d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554083
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 6, 2022
- Raw hash
- d2eb84fe8254b2cbd671dd2a5a8dcb7fbb3b83653d8c5de0054c0f0d0cf06c8b
Reporting entity
- Name
- Lincare Holdings Inc.norm: lincare holdings
- Domain
- lincare.com
Victim entity
- Name
- Lincare Holdings Inc.norm: lincare holdings
- Domain
- lincare.com
Incident
- Discovered
- Sep 26, 2021
- Materiality determined
- —
- Notification sent
- Apr 20, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 36 weeks(253 days from discovery to filing)
- Compliance flags
- CA 60-day late · 206d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 26, 2021→ Notified: Apr 20, 2022206d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.