HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Lincare Holdings Inc.
bd_a1db6594e58b1808 · schema v1 · pii pii-v1
Full breach record for Lincare Holdings Inc. →Lincare Holdings Inc. reported a security incident in California where unauthorized access to its network occurred between September 10 and September 29, 2021. The breach potentially exposed patient personal information, including names, addresses, and government identifiers. Lincare engaged outside cybersecurity experts, notified law enforcement, reset passwords, and offered one year of complimentary credit monitoring via Kroll. The incident status is contained, and the investigation into the full scope of affected individuals remains ongoing.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547919
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 24, 2021
- Raw hash
- 0d8a55b31d7f4f9961f3c944dc2bf7496b76970c3534fcbc68958bcfdf1d0da9
Reporting entity
- Name
- Lincare Holdings Inc.norm: lincare holdings
- Domain
- lincare.com
Victim entity
- Name
- Lincare Holdings Inc.norm: lincare holdings
- Domain
- lincare.com
Incident
- Discovered
- Sep 26, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.