HackingStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedBusiness Associate (HIPAA)IDENTITY_BASICPHIHEALTH_BASICLowContained
U.S. RENAL CARE, INC.
bd_7a38d061a22f57ea · schema v1 · pii pii-v1
Full breach record for U.S. RENAL CARE, INC. →HealthEC, a population health technology company, notified U.S. Renal Care, Inc. that an unknown actor accessed HealthEC's systems between July 14 and July 23, 2023, copying files containing patient names and health information. HealthEC secured systems, destroyed copied data, notified law enforcement, and offered credit monitoring. The incident is classified as a third-party supply chain breach involving unauthorized access and data exfiltration.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580670
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 7, 2024
- Raw hash
- e20650903ea2668d3b425055492f8ff24f2db985f6a6f7d05925eb687c2a3941
Reporting entity
- Name
- HealthEC LLCnorm: healthec
Victim entity
- Name
- U.S. RENAL CARE, INC.norm: us renal care
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 26, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notifying federal law enforcement
- Third party
- via HealthEC, LLC
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.