HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Choice Healthcare Insurance Brokers
bd_74c1aa8976e17e64 · schema v1 · pii pii-v1
Full breach record for Choice Healthcare Insurance Brokers →Choice Health Insurance, LLC notified South Carolina residents of a data breach where an unauthorized individual accessed a database via the internet on May 7, 2022. The incident resulted from a security configuration issue by a third-party provider. Exposed data included names, SSNs, Medicare IDs, DOBs, addresses, and health insurance info. Choice Health contained the breach, enhanced security with MFA, and offered 24 months of Experian IdentityWorks.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_6907d308ef4a84f4Oregon State AGfiled 2022-06-08Candidate
- bd_69cfc6cb3683011dCalifornia State AGfiled 2022-06-08Verified
- bd_6e57b7e10ecc0d63Montana State AGfiled 2022-06-08Verified
- bd_90b996d0d3e02bc4Washington State AGfiled 2022-06-08Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_9a82f36eea82ec3aNew Hampshire State AGfiled 2022-06-13(5d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2022/ChoiceHealthInsuranceLLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 8, 2022
- Raw hash
- 6d0e6e4c0bbb089c0e5c5a0afec253382dbe901869824283cb7669e994b0eb7b
Reporting entity
- Name
- Choice Healthcare Insurance Brokersnorm: choice healthcare insurance brokers
- Domain
- choice.healthcare
Victim entity
- Name
- Choice Healthcare Insurance Brokersnorm: choice healthcare insurance brokers
- Domain
- choice.healthcare
Incident
- Discovered
- May 14, 2022
- Materiality determined
- —
- Notification sent
- Jun 8, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.