HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCriticalContained
Panorama Eyecare
bd_69fc82cf197e9d9c · schema v1 · pii pii-v1
Full breach record for Panorama Eyecare →Panorama Eyecare, a healthcare provider based in Colorado, reported an external system breach (hacking) occurring between May 22, 2023, and June 4, 2023. The breach was discovered on May 9, 2024. The incident affected a total of 377,911 individuals, including 34 Maine residents. Acquired data included names, personal identifiers, financial account numbers, and credit/debit card numbers (with security codes/PINs). Panorama Eyecare sent written notifications on June 5, 2024, and provided 12 months of credit monitoring and identity theft protection services through Experian.
Leak gap clock✗ Leak >180d27 days discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 368 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_37a20ef7141a0c8fLeak Sitelockbit_3filed 2023-07-11(330d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_398e3ae8891cf770Vermont State AGfiled 2024-06-05Verified by operator
- bd_d080942e9d889006Montana State AGfiled 2024-06-05Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a6b8d97b-71cf-417b-9585-bdbc8251b836.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 5, 2024
- Raw hash
- 010cef0ab5958605b2ba38f570e62c87ac879fd2840bd50e1c18524212ea412a
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Panorama Eyecarenorm: panorama eyecare
- Domain
- panoramaeyecare.com
- Industry
- healthcare
Incident
- Discovered
- May 9, 2024
- Materiality determined
- —
- Notification sent
- Jun 5, 2024
- Affected individuals
- 377,911
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- Leak >180dME AG ≤30d · 27d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 9, 2024→ Filed with AG: Jun 5, 202427d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.