PhysicalTheftCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICHEALTH_BASICPHILowResolved
OptumRx
bd_7c4ce7add1b80823 · schema v1 · pii pii-v1
Full breach record for OptumRx →OptumRx notified California AG of a March 16, 2016 theft of an unencrypted vendor laptop in Indianapolis. The device contained PHI including names, addresses, health plan info, prescription data, and DOB. No financial data was compromised. OptumRx notified law enforcement, launched an investigation, and offered one year of LifeLock identity theft protection to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_af34254159aa5a6cMontana State AGfiled 2016-04-08Verified
- bd_4e3d61920c918becHHS OCRfiled 2016-04-12(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60898
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2016
- Raw hash
- 70c128954e3c6ac661894fe50459c01c659a717a8f9875dc107871b17c6679be
Reporting entity
- Name
- OptumRxnorm: optumrx
- Domain
- optumrx.com
Victim entity
- Name
- OptumRxnorm: optumrx
- Domain
- optumrx.com
Incident
- Discovered
- Mar 22, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.