HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
CBLPath
bd_5f83c87756f77a6f · schema v1 · pii pii-v1
Full breach record for CBLPath →CBLPath Inc. notified Delaware residents of a data security incident involving its vendor, Retrieval Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA). On May 15, 2019, AMCA experienced unauthorized access to a database containing patient information belonging to CBLPath. The incident involved AMCA's website payment page and database. Affected data included names, addresses, phone numbers, dates of birth, dates of service, balance information, and treatment provider information. CBLPath stopped using AMCA and engaged cybersecurity experts.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4df50073a599ae9bMontana State AGfiled 2019-07-15Verified
- bd_743b9b5cbfcd27bdHHS OCRfiled 2019-07-15Verified
- bd_8d620967253bb39aCalifornia State AGfiled 2019-07-15Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/07/CBLPath-Notification-Letters-Enclosure.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2019
- Raw hash
- 54351254801f06936ca9dba7a5d4da8571469cab3ac0bbf15901938ea57314c8
Reporting entity
- Name
- CBLPathnorm: cblpath
- Domain
- cblpath.com
Victim entity
- Name
- CBLPathnorm: cblpath
- Domain
- cblpath.com
Incident
- Discovered
- May 15, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.