Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Synergy Specialists Medical Group
bd_c20f97265971c9b0 · schema v1 · pii pii-v1
Full breach record for Synergy Specialists Medical Group →Synergy Specialists Medical Group, Inc. disclosed a phishing incident where fraudulent emails mimicking a DocuSign alert were sent to patients via a compromised Gmail account on December 9, 2016. The breach exposed patient registration forms, prescription/lab requests, voicemail transcriptions, and email addresses. The organization secured the account, engaged forensic specialists, and offered one year of Equifax Credit Watch Silver identity protection.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_119719b412e703c7Montana State AGfiled 2017-01-26(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66062
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2017
- Raw hash
- a15d463d4323e625c1c0516f09890a0e96be60d4b89bbce534cfaae3b7e8e117
Reporting entity
- Name
- Synergy Specialists Medical Groupnorm: synergy specialists medical
Victim entity
- Name
- Synergy Specialists Medical Groupnorm: synergy specialists medical
Incident
- Discovered
- Dec 9, 2016
- Materiality determined
- Dec 9, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.