AccidentalMisconfigurationCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICLowContained
mscripts
bd_99c22a97c6b2ad6b · schema v1 · pii pii-v1
Full breach record for mscripts →mscripts, LLC disclosed a misconfiguration of its cloud storage that left prescription management files accessible without authentication from September 30, 2016, to November 18, 2022. The exposed data included patient names, addresses, dates of birth, phone numbers, and prescription details (medication names, refill status). No SSNs or financial data were involved. mscripts engaged forensic investigators and changed access settings upon discovery.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0c0303edc104eef5Washington State AGfiled 2023-03-14Candidate
- bd_f4fa36f617dfea4cOregon State AGfiled 2023-03-14Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564325
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2023
- Raw hash
- 5c145ec54afafff97533383520a4a2fbbe35d5b2a6f961fff35c95f38c65d3a1
Reporting entity
- Name
- mscripts
Victim entity
- Name
- mscripts
Incident
- Discovered
- Nov 18, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.