HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Pacific Pulmonary Medical Group
bd_a14da3c468ce7bdd · schema v1 · pii pii-v1
Full breach record for Pacific Pulmonary Medical Group →Pacific Pulmonary Medical Group experienced a data incident involving compromised employee credentials to a third-party scheduling software. The incident occurred between October 21 and October 22, 2024, and was discovered on October 22, 2024. Personal information potentially affected includes identity and health data. The organization engaged a cybersecurity firm, notified law enforcement, and is offering credit monitoring services to affected individuals.
Leak gap clock⏱ Leak >30d10 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_c6f25a8a3412a7f5Leak Siteeverestfiled 2024-10-25(70d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-596931
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 3, 2025
- Raw hash
- 2874a4ea66015e2a149d799597ec93b00b528deb4a32617a7301d8288b9a8839
Reporting entity
- Name
- Pacific Pulmonary Medical Groupnorm: pacific pulmonary medical
- Domain
- pacificpulm.com
Victim entity
- Name
- Pacific Pulmonary Medical Groupnorm: pacific pulmonary medical
- Domain
- pacificpulm.com
Incident
- Discovered
- Oct 22, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Third-party software provider for scheduling
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(73 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.