HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Allcare Medical Management
bd_5e5f21e79920cdaf · schema v1 · pii pii-v1
Full breach record for Allcare Medical Management →Allcare Medical Management, Inc. reported unauthorized access to an employee email account between March 4 and April 20, 2024. The incident was detected on May 23, 2024. The breach potentially exposed PHI, SSNs, and other PII for patients of Family Planning Associates Medical Group, Inc. Allcare engaged forensic investigators, secured the account, and is offering credit monitoring.
Leak gap clock⏱ Leak >30d9 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_466f3da75151be6aLeak Sitelockbit_3filed 2024-05-15(67d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_92f52251c100907eHHS OCRfiled 2024-07-22Verified
- bd_3a21e436dcdbc881California State AGfiled 2024-08-02(11d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-589095
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2024
- Raw hash
- 4c5683974236b5e40040a3e8b713b545cf0f68399ce74c7c730e26a16b9ed9de
Reporting entity
- Name
- AllCare Health, Inc.norm: allcare health
Victim entity
- Name
- Allcare Medical Managementnorm: allcare medical management
- Domain
- allcare-med.com
Incident
- Discovered
- May 23, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.