AccidentalMisconfigurationCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPHILowContained
Sunshine Behavioral Health Group LLC
bd_aeade4f412fb254a · schema v1 · pii pii-v1
Full breach record for Sunshine Behavioral Health Group LLC →Sunshine Behavioral Health Group, LLC notified individuals that a cloud-based system storing patient records was inadvertently configured to allow public internet access. The company became aware of the misconfiguration on September 4, 2019, and immediately changed settings and removed records from general access. Affected data included names, addresses, credit/debit card numbers, expiration dates, security codes, and electronic signatures. The company offered 24 months of identity protection services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3d7e174363873970Montana State AGfiled 2020-01-21Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-186209
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2020
- Raw hash
- d0c8d2a4ab53572776c52b647d41e8a438c05f9e697058d21894a14a62c3121d
Reporting entity
- Name
- Sunshine Behavioral Health Group LLCnorm: sunshine behavioral health
Victim entity
- Name
- Sunshine Behavioral Health Group LLCnorm: sunshine behavioral health
Incident
- Discovered
- Sep 4, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPHI
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 20 weeks(139 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.