MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Assured Imaging
bd_6275192d8f7b8ebb · schema v1 · pii pii-v1
Full breach record for Assured Imaging →Assured Imaging, a healthcare technology provider, disclosed a ransomware incident on May 19, 2020. An unknown actor encrypted electronic medical records systems between May 15 and May 17, 2020, and exfiltrated limited patient and employee data, including names, SSNs, driver's license numbers, and bank account numbers. Assured engaged forensic specialists, restored systems, notified HHS, and offered 12 months of credit monitoring.
California clockDiscovered May 19, 2020 → Notified May 19, 20200d ✓ CA 60-day OK15 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4fcc628f54aa63abWashington State AGfiled 2020-08-31Candidate
- bd_ab34b9b0d06ce0ccMontana State AGfiled 2020-08-31Candidate
- bd_d123cac72216b28aOregon State AGfiled 2020-08-31Candidate
- bd_3170bc86fa616733HHS OCRfiled 2020-08-27(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193602
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2020
- Raw hash
- 1e32a0e40fb4fe15f638071d675f64e36a10de6b54fc1f3d306b9630acce48db
Reporting entity
- Name
- Assured Imagingnorm: assured imaging
Victim entity
- Name
- Assured Imagingnorm: assured imaging
Incident
- Discovered
- May 19, 2020
- Materiality determined
- —
- Notification sent
- May 19, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human ServicesNotified other government regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(104 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 19, 2020→ Notified: May 19, 20200d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.