MalwareRansomwareStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedMulti-Stage ChainRansom DemandedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCriticalContained
NextGen
bd_a69f8843f48c03cb · schema v1 · pii pii-v1
Full breach record for NextGen →NextGen Healthcare, Inc. reported a cybersecurity incident in January 2023 involving a BlackCat ransomware attack. The breach was facilitated by stolen client credentials, allowing unauthorized access to systems. Over 1.04 million patient records were affected, exposing PHI, names, DOBs, and SSNs. NextGen engaged forensic investigators, notified law enforcement, and offered credit monitoring to affected individuals.
Leak gap clock⏱ Leak >90d14 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by alphv about this victim predates this filing by 107 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e422ad9fcbed65aeLeak Sitealphvfiled 2023-01-17(107d gap)Verified by operator
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2023/NextGenHealthcare.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 4, 2023
- Raw hash
- bece0e870ab06ba474df93a657c54730cb436e8bb84dc94622734ac4059d1992
Reporting entity
- Name
- NextGennorm: nextgen
- Domain
- nextgen.com
- Industry
- Healthcare Software
Victim entity
- Name
- NextGennorm: nextgen
- Domain
- nextgen.com
- Industry
- Healthcare Software
Incident
- Discovered
- Jan 28, 2023
- Materiality determined
- May 8, 2023
- Notification sent
- Apr 28, 2023
- Affected individuals
- 1,049,375
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified South Carolina Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(96 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.