HackingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPHIIDENTITY_BASICHEALTH_BASICLowContained
Tiburcio Vasquez Health Center
bd_be5c2348e778287a · schema v1 · pii pii-v1
Full breach record for Tiburcio Vasquez Health Center →Tiburcio Vasquez Health Center Inc. notified the California AG of a security incident involving its vendor, CaptureRx. Unauthorized access occurred on Feb 6, 2021, and was discovered on Feb 19, 2021. Affected data included names, dates of birth, and prescription information (PHI). CaptureRx investigated, secured systems, and is enhancing policies and training.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3635841aa0311a33HHS OCRfiled 2021-06-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542134
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 22, 2021
- Raw hash
- d8b131357033b4db9e633f23c01878691f9573dd02b2d980dc36bf46de8e1cd9
Reporting entity
- Name
- Tiburcio Vasquez Health Centernorm: tiburcio vasquez health center
- Domain
- tvhc.org
Victim entity
- Name
- Tiburcio Vasquez Health Centernorm: tiburcio vasquez health center
- Domain
- tvhc.org
Incident
- Discovered
- Feb 19, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via CaptureRx
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.