CALIFORNIASocial EngineeringHealthcareHealthcarePhishingStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
Allcare Medical Management
bd_92f52251c100907e · schema v1 · pii pii-v1
Full breach record for Allcare Medical Management →Allcare Medical Management Incorporated, a business associate based in CA, reported to HHS on 2024-07-22 a Hacking/IT Incident (email phishing) affecting 16,378 individuals. An employee was the subject of an email phishing scheme that exposed PHI including names, dates of birth, Social Security numbers, and other demographic information. Breached information located on Email. The BA notified HHS, affected individuals, and media; implemented additional safeguards; and retrained staff on email security. OCR provided technical assistance.
Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 67 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_466f3da75151be6aLeak Sitelockbit_3filed 2024-05-15(67d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_5e5f21e79920cdafCalifornia State AGfiled 2024-07-22Candidate
- bd_3a21e436dcdbc881California State AGfiled 2024-08-02(11d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 22, 2024
- Raw hash
- 39e64adf634d37ec024be59ff0263c11611d2b8fb18ced2ab04b52f85333380e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- AllCare Health, Inc.norm: allcare health
- Industry
- Business Associate
Victim entity
- Name
- Allcare Medical Managementnorm: allcare medical management
- Domain
- allcare-med.com
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 16,378
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance regarding the HIPAA Rules.
- Initial access
- phishing_attachment
Compliance
- Compliance flags
- Leak >30dHHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.