MalwareRansomwareData EncryptedCustomer Data InvolvedBusiness Associate (HIPAA)PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Reventics
bd_9b7cb14095be9c9f · schema v1 · pii pii-v1
Full breach record for Reventics →Reventics, LLC, a revenue cycle management company for healthcare providers, detected a cyber-intruder who encrypted and potentially accessed information on its servers on December 15, 2022. The incident involved the unauthorized acquisition of PII and PHI, including names, addresses, dates of birth, medical record numbers, driver's licenses, and clinical data. Reventics engaged forensic consultants, contained the threat, and is offering identity theft protection services to affected individuals.
California clockDiscovered Dec 15, 2022 → Notified Mar 1, 202376d ✗ CA 60-day late25 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_18f543cf58f515fdWashington State AGfiled 2023-06-05Candidate
- bd_4ffc1062c3553267Oregon State AGfiled 2023-06-20(15d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567606
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 5, 2023
- Raw hash
- b889639f3b092aafba7be069f729404b94fb7424bb6a697a721e2a135cc47e16
Reporting entity
- Name
- Reventicsnorm: reventics
- Domain
- reventics.com
Victim entity
- Name
- Reventicsnorm: reventics
- Domain
- reventics.com
Incident
- Discovered
- Dec 15, 2022
- Materiality determined
- —
- Notification sent
- Mar 1, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcementPrepared regulatory notices
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- CA 60-day late · 76dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 15, 2022→ Notified: Mar 1, 202376d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.