HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)PHIHEALTH_BASICIDENTITY_BASICLowContained
Medical Eye Services, Inc.
bd_6beb8ba0bda9123f · schema v1 · pii pii-v1
Full breach record for Medical Eye Services, Inc. →Blue Shield of California notified members that a contracted vendor managing vision benefits was compromised in the global MOVEit data security incident. An unauthorized third party exploited an unknown vulnerability in the MOVEit server to exfiltrate information on May 28 and May 31, 2023. The vendor discovered the breach on August 23, 2023. Affected data may include member eligibility, authorized third parties, and vision claims processing information. Blue Shield is offering complimentary credit monitoring and identity restoration services through Kroll.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_8695a245d6b38536Maine State AGfiled 2023-11-17Verified
- bd_b9bc0c3a55fd236eOregon State AGfiled 2023-11-17Verified
- bd_c0b9305f53e1673eMaine State AGfiled 2023-11-15(2d gap)Verified
- bd_8fd3b5758701dc53California State AGfiled 2023-11-14(3d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 75d gap
- bd_97132facec254d63Montana State AGfiled 2023-11-14(3d gap)Candidate
- bd_bac779c9da975873Oregon State AGfiled 2023-11-14(3d gap)Verified
- bd_57de58eb876f18d7New Hampshire State AGfiled 2023-11-22(5d gap)Verified
- bd_e353aefdc5628e28California State AGfiled 2024-01-30(74d gap)Verified
- bd_98132492ce988ce0Maine State AGfiled 2024-01-31(75d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576743
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2023
- Raw hash
- f21decc8ecdb3c9446f1dad7e0c575318298d905ff22421c2635f01de634d0b5
Reporting entity
- Name
- Medical Eye Services, Inc.norm: medical eye
- Domain
- medeye.net
Victim entity
- Name
- Medical Eye Services, Inc.norm: medical eye
- Domain
- medeye.net
Incident
- Discovered
- Aug 23, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reported the matter to the FBI
- Third party
- via Contracted vendor managing vision benefits
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.