HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
PaperlessPay Corporation
bd_9b3b2307d4d4abe3 · schema v1 · pii pii-v1
Full breach record for PaperlessPay Corporation →Prisma Health, a South Carolina healthcare provider, notified employees of a data breach involving its vendor, PaperlessPay Corporation. Unauthorized access to PaperlessPay's servers occurred around February 18, 2020, exposing employee names, addresses, and Social Security numbers. Prisma Health offered one year of credit monitoring and identity theft insurance via Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2020/PrismaHealth.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 23, 2020
- Raw hash
- 4103f23866365622e052d37fda94500123501a4a50cd823dc38ed8ff986fa451
Reporting entity
- Name
- Prisma Healthnorm: prisma health
Victim entity
- Name
- PaperlessPay Corporationnorm: paperlesspay
- Domain
- paperlesspaycorp.com
Incident
- Discovered
- Feb 19, 2020
- Materiality determined
- —
- Notification sent
- Jul 20, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(155 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.