HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
DAP Health, Inc.
bd_a8047abe2d731672 · schema v1 · pii pii-v1
Full breach record for DAP Health, Inc. →DAP Health, Inc. detected suspicious activity in its email environment on July 22, 2024. An unauthorized actor accessed and acquired files and data stored within the email environment. The breach occurred on July 8, 2024. Affected data includes personal information of employees, patients, and clients, potentially including names, addresses, SSNs, and health information. DAP Health engaged third-party cybersecurity firms, conducted a forensic investigation, and is offering 12 months of credit monitoring and fraud assistance to affected individuals.
California clockDiscovered Jul 22, 2024 → Notified Dec 26, 2024157d ✗ CA 60-day late22 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-596662
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 26, 2024
- Raw hash
- 8cf968f869c8edde9497d3aee4b93d58bcbcc1bd39038ace33f7856ce842e598
Reporting entity
- Name
- DAP Health, Inc.norm: dap health
Victim entity
- Name
- DAP Health, Inc.norm: dap health
Incident
- Discovered
- Jul 22, 2024
- Materiality determined
- —
- Notification sent
- Dec 26, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Filed notification with California Attorney General
Compliance
- Time to disclose
- 22 weeks(157 days from discovery to filing)
- Compliance flags
- CA 60-day late · 157d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 22, 2024→ Notified: Dec 26, 2024157d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.