HackingCustomer Data InvolvedData ExfiltratedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
OnePoint Patient Care
bd_b80758011a6c8438 · schema v1 · pii pii-v1
Full breach record for OnePoint Patient Care →OnePoint Patient Care detected suspicious activity on its network on August 8, 2024. An investigation revealed that an unauthorized third party accessed patient data between August 6 and August 8, 2024. Affected data includes names, addresses, medical record numbers, diagnoses, Social Security numbers, and prescription information. The company engaged forensic investigators, contained the incident, notified law enforcement, and offered one year of credit monitoring to affected individuals.
Leak gap clock⏱ Leak >90d15 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_3f7e05d630c49768Leak Siteinc_ransomfiled 2024-09-12(70d gap)Candidate
- bd_4fa10f6d814e255dLeak Siteinc_ransomfiled 2024-08-06(108d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_a04fe40ab837a151Oregon State AGfiled 2024-11-22Verified
- bd_576ce027515e4896Oregon State AGfiled 2024-10-23(30d gap)Verified
- bd_be89389a8bf3ebebMontana State AGfiled 2024-10-23(30d gap)Verified
- bd_8adcaa2abc34f2c0California State AGfiled 2025-02-06(76d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 76d gap
- bd_f55bcb1e60892a2aOregon State AGfiled 2025-02-06(76d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595288
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2024
- Raw hash
- e4984c2c9931a300fa6450fd010db163ab7ac4295d20ac27e60eb8c2e5000eb9
Reporting entity
- Name
- OnePoint Patient Carenorm: onepoint patient care
Victim entity
- Name
- OnePoint Patient Carenorm: onepoint patient care
Incident
- Discovered
- Aug 8, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.