MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
PracticeMax
bd_c3ddc5b7d5967e6f · schema v1 · pii pii-v1
Full breach record for PracticeMax →PracticeMax, a business management and IT solutions provider, disclosed a ransomware incident affecting its network from April 17, 2021, to May 5, 2021. The attack encrypted data and allowed unauthorized access to one server and limited email accounts. While no confirmed data disclosure was found, systems may have contained PII, PHI, SSNs, and financial data. PracticeMax disconnected systems, engaged forensic specialists, notified law enforcement, and offered one year of identity monitoring via Kroll.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3bbfba4a3095fb69South Carolina State AGfiled 2022-06-10Verified
- bd_41650c90bc215032Maine State AGfiled 2022-06-10Verified
- bd_f61da3d5b25643d6Oregon State AGfiled 2022-06-10Verified
- bd_63b71b27f7b47bdfNew Hampshire State AGfiled 2022-06-14(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554209
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2022
- Raw hash
- 82f5551ddc20cb6a187aad81bdf3ddb3aa83bfd6f5cac93f23ef2f69d00d3303
Reporting entity
- Name
- PracticeMaxnorm: practicemax
- Domain
- practicemax.com
Victim entity
- Name
- PracticeMaxnorm: practicemax
- Domain
- practicemax.com
Incident
- Discovered
- May 1, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified relevant regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 months(405 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.