Social EngineeringPhishingData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTMINORMediumContained
Medsurant Holdings, LLC
bd_cdffc9b5517e1fd1 · schema v1 · pii pii-v1
Full breach record for Medsurant Holdings, LLC →Medsurant Holdings, LLC, a healthcare services provider, disclosed a breach affecting patient and employee data. An unknown actor gained access via a suspicious email on September 30, 2021, after initial access between September 23-30, 2021. Data exfiltrated included names, addresses, and government IDs. A second access occurred on November 12, 2021, involving limited encryption. Medsurant notified law enforcement and HHS, offering credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f7bbed94b59f6f6aMontana State AGfiled 2022-03-25Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552001
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2022
- Raw hash
- 4a0eb46de7eb9d0cdc405c6c9705bf633456b1092bedcc96d07a69074fdc4b4d
Reporting entity
- Name
- Medsurant Holdings, LLCnorm: medsurant holdings
Victim entity
- Name
- Medsurant Holdings, LLCnorm: medsurant holdings
Incident
- Discovered
- Sep 30, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementNotified the U.S. Department of Health and Human ServicesNotified other government regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 25 weeks(176 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.