CBLPath
bd_8d620967253bb39a · schema v1 · pii pii-v1
Full breach record for CBLPath →2 incidents on fileCBLPath, Inc. notified patients of a data security incident involving its vendor, Retrieval Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA). The incident involved unauthorized access to AMCA's database and payment page, potentially exposing patient names, addresses, phone numbers, dates of birth, service dates, balance information, and treatment provider information. The breach occurred between August 1, 2018, and March 30, 2019. CBLPath was notified on May 15, 2019, and immediately ceased using AMCA for collections. Cyber security experts were engaged to assist in the investigation.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 1, 2018
Begins
May 15, 2019
Discovered
Jul 15, 2019
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_4df50073a599ae9b2019-07-15Verified
- Delaware State AGbd_5f83c87756f77a6f2019-07-15Verified
- HHS OCRbd_743b9b5cbfcd27bd2019-07-15Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.