HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIALMediumContained
Managed Care of North America, Inc.
bd_85569ed740a38ff7 · schema v1 · pii pii-v1
Full breach record for Managed Care of North America, Inc. →Managed Care of North America, Inc. (MCNA) disclosed a data breach where a cybercriminal accessed and copied information from its computer system between February 26 and March 7, 2023. MCNA became aware of the unauthorized activity on March 6, 2023. Affected data includes names, addresses, dates of birth, Social Security numbers, driver's license numbers, health insurance information, and dental care records. MCNA engaged a special investigation team, contacted law enforcement, and is offering identity theft protection services to affected individuals.
California clockDiscovered Mar 6, 2023 → Notified May 26, 202381d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_bd79d24c6d422b05Washington State AGfiled 2023-05-26Verified
- bd_c6deca26eef87932Montana State AGfiled 2023-05-26Verified
- bd_d1e6071fa4c9eb84Maine State AGfiled 2023-05-26Verified
- bd_d284c416d84338c3Vermont State AGfiled 2023-05-26Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567260
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2023
- Raw hash
- c6ddff7b6c4ca8f345f3eab3ca776b0956adbe128cdce6daef31d1701b6e1bb8
Reporting entity
- Name
- Managed Care of North America, Inc.norm: managed care of north america
Victim entity
- Name
- Managed Care of North America, Inc.norm: managed care of north america
Incident
- Discovered
- Mar 6, 2023
- Materiality determined
- —
- Notification sent
- May 26, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified state Medicaid agency
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- CA 60-day late · 81d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 6, 2023→ Notified: May 26, 202381d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.