AccidentalMisconfigurationData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICPHIHEALTH_BASICMediumContained
Choice Healthcare Insurance Brokers
bd_69cfc6cb3683011d · schema v1 · pii pii-v1
Full breach record for Choice Healthcare Insurance Brokers →Choice Health Insurance, LLC reported a data breach affecting California residents. On May 7, 2022, an unauthorized individual accessed a database exposed to the internet due to a third-party service provider's security misconfiguration. The incident involved PHI, SSNs, and Medicare IDs. Choice Health contained the breach, implemented MFA, and offered 24 months of Experian IdentityWorks.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_6907d308ef4a84f4Oregon State AGfiled 2022-06-08Candidate
- bd_6e57b7e10ecc0d63Montana State AGfiled 2022-06-08Verified
- bd_74c1aa8976e17e64South Carolina State AGfiled 2022-06-08Verified
- bd_90b996d0d3e02bc4Washington State AGfiled 2022-06-08Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_9a82f36eea82ec3aNew Hampshire State AGfiled 2022-06-13(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554136
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 8, 2022
- Raw hash
- 2c5c4784df497824f7ef5633de68d162aecf36e041445178836b46358efbebe0
Reporting entity
- Name
- Choice Healthcare Insurance Brokersnorm: choice healthcare insurance brokers
- Domain
- choice.healthcare
Victim entity
- Name
- Choice Healthcare Insurance Brokersnorm: choice healthcare insurance brokers
- Domain
- choice.healthcare
Incident
- Discovered
- May 14, 2022
- Materiality determined
- Jun 8, 2022
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.