MultipleVulnerability ExploitRansomwareData MishandlingSupply Chain (3P Vendor)Data EncryptedCustomer Data InvolvedBusiness Associate (HIPAA)PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Spectrum Eye Physicians
bd_cb60c64bcfde2afc · schema v1 · pii pii-v1
Full breach record for Spectrum Eye Physicians →Spectrum Eye Physicians notified patients of two data breaches involving third-party vendor Eye Care Leaders (ECL). The first involved a vulnerability in the Alta Payment Portal allowing unauthorized access to payment receipts (Oct 2021). The second was a ransomware attack on ECL's myCare Integrity EMR system (Dec 2021) where attackers deleted databases. Spectrum discovered the issues in May 2022. Affected data includes PHI, financial account details, and patient identities. Spectrum terminated contracts with ECL and migrated to new vendors.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555119
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 11, 2022
- Raw hash
- 76176b15e957ec9c408016cad79d27a7d693317f02c4093f7bf3e5d3ead09e6c
Reporting entity
- Name
- Spectrum Eye Physiciansnorm: spectrum eye physicians
- Domain
- spectrumeye.com
Victim entity
- Name
- Spectrum Eye Physiciansnorm: spectrum eye physicians
- Domain
- spectrumeye.com
Incident
- Discovered
- May 19, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filing a Breach Report with the Office for Civil Rights (OCR)
- Third party
- via Eye Care Leaders
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.