HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICHEALTH_BASICLowContained
Western Pathology
bd_853b687bcda4aad7 · schema v1 · pii pii-v1
Full breach record for Western Pathology →Western Pathology Consultants, Ltd. notified California regulators of a data security incident involving its third-party vendor, Retrieval Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA). The breach occurred between August 1, 2018, and March 30, 2019, involving unauthorized access to an AMCA database containing patient information. Western Pathology engaged cybersecurity experts and terminated its relationship with AMCA.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_dfcde8da0f70df2aMontana State AGfiled 2019-07-24Verified
- bd_a3e215f21fb528acHHS OCRfiled 2019-07-25(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149197
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 24, 2019
- Raw hash
- a187744b7f427f4bb8a454651e4cf2ddab13f7da06966f6869b8eebd5e4280b2
Reporting entity
- Name
- Western Pathologynorm: western pathology
- Domain
- westernpathology.com
Victim entity
- Name
- Western Pathologynorm: western pathology
- Domain
- westernpathology.com
Incident
- Discovered
- May 15, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.