HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
CBLPath
bd_8d620967253bb39a · schema v1 · pii pii-v1
Full breach record for CBLPath →CBLPath, Inc. notified California regulators of a data security incident involving its third-party vendor, Retrieval Masters Creditors Bureau (d/b/a American Medical Collection Agency or AMCA). On May 15, 2019, CBLPath was informed that AMCA experienced unauthorized access to a database containing patient information. The breach affected data including names, addresses, dates of birth, and treatment provider information. CBLPath terminated its relationship with AMCA and engaged cybersecurity experts for investigation.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4df50073a599ae9bMontana State AGfiled 2019-07-15Verified
- bd_5f83c87756f77a6fDelaware State AGfiled 2019-07-15Verified
- bd_743b9b5cbfcd27bdHHS OCRfiled 2019-07-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148938
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2019
- Raw hash
- 3772976d41f438e669b7226d8d7a3a53ba74dd7b1aaf64ac43d5a9204bdbe0d0
Reporting entity
- Name
- CBLPathnorm: cblpath
- Domain
- cblpath.com
Victim entity
- Name
- CBLPathnorm: cblpath
- Domain
- cblpath.com
Incident
- Discovered
- May 15, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.