Social EngineeringHealthcareTechnologyHealthcarePhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedData ExfiltratedDelayed DiscoveryPIIPHIPCICREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICAUTHENTICATIONMediumResolved
Ciox Health
bd_b3dc1935edf30ecf · schema v1 · pii pii-v1
Full breach record for Ciox Health →Ciox Health LLC (d/b/a Datavant Group), a healthcare data technology company, reported a May 2024 phishing email attack in which an unauthorized party gained access to a single employee mailbox between May 8–9, 2024. Data potentially affected included names, addresses, SSNs, financial account information, driver's licenses, passports, health information, and employee credentials. 17 Maine residents were affected out of 49,454 total. Kroll 24-month identity monitoring was offered.
Maine clockDiscovered May 9, 2024 → Filed with AG Feb 11, 2025278d ✗ ME AG >90d40 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a00e2846daad891eMontana State AGfiled 2025-02-11Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1722fefd-4dce-4e2b-b62b-bae31991345f.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2025
- Raw hash
- 72a1f03d74cb2ac11bb94347c2caf425779626d55e0e6838d8407b3623650f0a
Reporting entity
- Name
- Ciox Healthnorm: ciox health
- Domain
- datavant.com
- Industry
- Healthcare
Victim entity
- Name
- Ciox Healthnorm: ciox health
- Domain
- datavant.com
- Industry
- Healthcare
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- May 9, 2024
- Materiality determined
- —
- Notification sent
- Dec 6, 2024
- Affected individuals
- 17
- Data types
- PIIPHIPCICREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICAUTHENTICATION
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Supplemental notification submitted to Maine AG on February 11, 2025 by outside counsel via webform
- Initial access
- phishing_link
Compliance
- Time to disclose
- 40 weeks(278 days from discovery to filing)
- Compliance flags
- ME AG >90d · 278dME resident >180d · 211d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 9, 2024→ Filed with AG: Feb 11, 2025278d 90 days ME AG >90d Maine Discovered: May 9, 2024→ Notified: Dec 6, 2024211d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.