HackingHealthcareProfessional ServicesHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryBusiness Associate (HIPAA)PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Physician's Business Office
bd_6b5ee27620c5e075 · schema v1 · pii pii-v1
Full breach record for Physician's Business Office →Physician's Business Office, Inc. (PBO), a medical practice management and administrative services firm, experienced unauthorized access to its computer systems in April 2022. An unknown individual may have accessed or acquired personal and protected health information including names, addresses, dates of birth, SSNs, driver's license numbers, medical treatment/diagnosis information, disability codes, prescription information, and health insurance account data. PBO engaged a digital forensics firm and notified affected individuals in September 2022.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_17318e6d4cd7304fNew Hampshire State AGfiled 2022-09-23Verified
- bd_22d63588c8f3bfb9Maine State AGfiled 2022-09-23Candidate
- bd_c8e23e57dc38b951Montana State AGfiled 2022-09-23Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557575
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 23, 2022
- Raw hash
- 1b43bed2de681912085a30960e46da70149e37ff36f47d3f311ba04789086dc5
Reporting entity
- Name
- Physician's Business Officenorm: physician s business office
- Industry
- Medical practice management and administrative services
Victim entity
- Name
- Physician's Business Officenorm: physician s business office
- Industry
- Medical practice management and administrative services
- Industry
- HealthcarellmProfessional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 23, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.