HackingCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICEMPLOYMENTLowContained
SAV-RX
bd_814ec92dc4fd6b82 · schema v1 · pii pii-v1
Full breach record for SAV-RX →A&A Services d/b/a Sav-Rx experienced unauthorized access to its IT systems starting around October 3, 2023, discovered on October 8, 2023. An external actor accessed non-clinical systems containing protected health information (PHI) and employee personal data. The company engaged forensic experts, contained the incident, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6eca727782b22844Vermont State AGfiled 2024-05-24Verified
- bd_a711b87c3aaa61fbMontana State AGfiled 2024-05-24Verified
- bd_e27bf8cc5118b8faDelaware State AGfiled 2024-05-24Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585926
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2024
- Raw hash
- 3a8fe93285fd714aa3398fdea0e8a6f3835fb0e4f8d4164c58cbe9f628fe60b9
Reporting entity
- Name
- SAV-RXnorm: sav rx
- Domain
- api.savrx.com
Victim entity
- Name
- SAV-RXnorm: sav rx
- Domain
- api.savrx.com
Incident
- Discovered
- Oct 8, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 33 weeks(229 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.