HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Luque Chiropractic, Inc.
bd_74345c8e546d13f6 · schema v1 · pii pii-v1
Full breach record for Luque Chiropractic, Inc. →Luque Chiropractic, Inc. disclosed a data security incident involving an Amazon S3 storage account accessible to a security researcher. The breach exposed patient names, addresses, diagnoses, dates of birth, treatment details, and Social Security numbers for individuals between May 1, 2016, and September 11, 2016. Luque offered credit monitoring and identity restoration services to affected patients.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b4fa8f444248994fHHS OCRfiled 2016-11-17Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64959
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2016
- Raw hash
- eed3462654eeee423c1820510429b999b063ec0379e5590e10eb82a9e9dc1f92
Reporting entity
- Name
- Luque Chiropractic, Inc.norm: luque chiropractic
Victim entity
- Name
- Luque Chiropractic, Inc.norm: luque chiropractic
Incident
- Discovered
- Sep 18, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.