HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
American Health Information Management Association
bd_a47b85b0a74b55b9 · schema v1 · pii pii-v1
Full breach record for American Health Information Management Association →AHIMA notified California AG of a data breach affecting online store customers. Suspicious activity detected Oct 13, 2020. Compromised data included names, card numbers, expiration dates, and security codes for purchases made between July-Oct 2020. AHIMA engaged forensic investigators, notified the FBI, and offered 12 months of identity theft protection.
California clockDiscovered Oct 13, 2020 → Notified Jan 5, 202184d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_a52d2472c20f3d96Montana State AGfiled 2021-01-05(1d gap)Candidate
- bd_7dcc005f046faba2Maine State AGfiled 2021-01-10(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198276
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 6, 2021
- Raw hash
- 1125f101b6bd5007a4430642e5225dbc5cbd6c65bef02bce9972eea10b8bebb4
Reporting entity
- Name
- American Health Information Management Associationnorm: american health information management
Victim entity
- Name
- American Health Information Management Associationnorm: american health information management
Incident
- Discovered
- Oct 13, 2020
- Materiality determined
- —
- Notification sent
- Jan 5, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 13, 2020→ Notified: Jan 5, 202184d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.