HackingStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainSupply Chain (3P Vendor)PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTCriticalContained
Connexin Software, Inc.
bd_a4c6d762fac543f5 · schema v1 · pii pii-v1
Full breach record for Connexin Software, Inc. →Connexin Software, Inc. (doing business as Office Practicum) notified the South Carolina Office of Consumer Affairs of a data breach detected on August 26, 2022. An unauthorized party accessed an offline set of patient data used for conversion and troubleshooting, affecting approximately 2.2 million pediatric patients. The incident involved ransomware (LockBit 3.0) and data exfiltration. Connexin provided credit monitoring and identity protection services to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1714e873907ffbd7California State AGfiled 2022-11-14Verified
- bd_5b34d1b03ca82c40Oregon State AGfiled 2022-11-14Verified
- bd_a2703f9eb481b201Montana State AGfiled 2022-11-14Verified
- bd_fd18f9fae5f5fe0aHHS OCRfiled 2022-11-11(3d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2022/ConnexinSoftwareInc.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 14, 2022
- Raw hash
- 490a448ed60a8bacd006ac60f68e27b4b9cbe299de13d080c52dd82248010f44
Reporting entity
- Name
- Connexin Software, Inc.norm: connexin software
Victim entity
- Name
- Connexin Software, Inc.norm: connexin software
Incident
- Discovered
- Aug 26, 2022
- Materiality determined
- —
- Notification sent
- Nov 30, 2022
- Affected individuals
- 2,216,365
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.