Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
American Anesthesiology, Inc.
bd_c1cbfd29ce17dc04 · schema v1 · pii pii-v1
Full breach record for American Anesthesiology, Inc. →American Anesthesiology, Inc. notified California regulators of a security event involving its business associate, MEDNAX Services, Inc. An unauthorized party accessed Microsoft Office 365 email accounts via phishing between June 17 and June 22, 2020. Patient personal information, including names, SSNs, health insurance details, and medical records, was stored in the compromised accounts. The breach was contained, and affected patients were offered credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1c89d410047f27b1HHS OCRfiled 2021-01-08Verified
- bd_3f02b387fd1197eaOregon State AGfiled 2021-01-08Verified
- bd_6905374190db86e6Maine State AGfiled 2021-01-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198346
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 8, 2021
- Raw hash
- 4be3f7adfec09d5208aae1ec98c03ca6fc88191b0a99e025b11653b88bfbd2cc
Reporting entity
- Name
- American Anesthesiology, Inc.norm: american anesthesiology
Victim entity
- Name
- American Anesthesiology, Inc.norm: american anesthesiology
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- Jul 16, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 25 weeks(176 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.