HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
The Urology Center of Colorado
bd_ac1e0b66488c2e14 · schema v1 · pii pii-v1
Full breach record for The Urology Center of Colorado →The Urology Center of Colorado (TUCC) notified California regulators of a data breach occurring September 7-8, 2021. An unauthorized individual accessed parts of TUCC's network, potentially exposing patient names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, diagnoses, treatment costs, and health insurance information. TUCC reset passwords, updated security policies, and offered credit monitoring and identity protection services to affected individuals. The investigation was completed on November 1, 2021.
California clockDiscovered Sep 8, 2021 → Notified Nov 10, 202163d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_922eedef44e0657cHHS OCRfiled 2021-11-05(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547437
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 10, 2021
- Raw hash
- d33128330af0f255b0b76237986ae379e9d5d4035e0f81343673269b7db030bf
Reporting entity
- Name
- The Urology Center of Coloradonorm: the urology center of colorado
- Industry
- healthcare
Victim entity
- Name
- The Urology Center of Coloradonorm: the urology center of colorado
- Industry
- healthcare
Incident
- Discovered
- Sep 8, 2021
- Materiality determined
- —
- Notification sent
- Nov 10, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- CA 60-day late · 63d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 8, 2021→ Notified: Nov 10, 202163d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.