PracticeMax
bd_acb3b8ca891d05d1 · schema v1 · pii pii-v1
Full breach record for PracticeMax →PracticeMax Inc. reported a ransomware attack on its network occurring between April 17, 2021, and May 5, 2021. The incident involved unauthorized access to a server containing Protected Health Information (PHI) and personally identifiable information (PII), including names, dates of birth, addresses, phone numbers, and Social Security Numbers for some individuals. PracticeMax engaged legal counsel and a forensic firm, restored system access, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring via Equifax. The breach impacted patients of DaVita's VillageHealth program.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e41b90ca71bec287California State AGfiled 2021-10-15(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-546631
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 19, 2021
- Raw hash
- ec42d7a26ae20a9b3c12936471d4d304f1e469dc5e371222a62427c51cc37443
Reporting entity
- Name
- PracticeMaxnorm: practicemax
- Domain
- practicemax.com
Victim entity
- Name
- PracticeMaxnorm: practicemax
- Domain
- practicemax.com
Incident
- Discovered
- May 1, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulatory authorities and law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(171 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.