HackingStolen CredentialsDelayed DiscoveryIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICIDENTITY_BASICHighResolved
Aveanna Healthcare LLC
bd_9995f453fd70a8fa · schema v1 · pii pii-v1
Full breach record for Aveanna Healthcare LLC →Aveanna Healthcare reported a data breach affecting 5,004 California residents. Unauthorized access occurred to employee email accounts between July 9, 2019, and August 24, 2019. The incident involved the potential exposure of Social Security numbers, driver's licenses, bank account information, and medical/health insurance data. Aveanna engaged forensic specialists, secured accounts, implemented MFA, and offered 12 months of credit monitoring to affected individuals.
California clockDiscovered Aug 24, 2019 → Notified Feb 14, 2020174d ✗ CA 60-day late25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_16f4b4559fe49649HHS OCRfiled 2020-02-14Candidate
- bd_d63cfe491add01dbWashington State AGfiled 2020-02-14Verified
- bd_dedaafa6f4714218Montana State AGfiled 2020-02-14Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-187372
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2020
- Raw hash
- f27539cda450f9508a576e2bd9348f4428906b77dc2b153e3d8921da5f06f839
Reporting entity
- Name
- Aveanna Healthcare LLCnorm: aveanna healthcare
- Domain
- aveanna.com
Victim entity
- Name
- Aveanna Healthcare LLCnorm: aveanna healthcare
- Domain
- aveanna.com
Incident
- Discovered
- Aug 24, 2019
- Materiality determined
- —
- Notification sent
- Feb 14, 2020
- Affected individuals
- 5,004
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Provided notice to state and federal regulatorsNotified the three major credit reporting agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(174 days from discovery to filing)
- Compliance flags
- CA 60-day late · 174d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 24, 2019→ Notified: Feb 14, 2020174d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.