HackingCustomer Data InvolvedData ExfiltratedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
OnePoint Patient Care
bd_ce0fa04e2346a79f · schema v1 · pii pii-v1
Full breach record for OnePoint Patient Care →OnePoint Patient Care detected suspicious activity on its network on August 8, 2024. An investigation revealed that an unauthorized third party accessed patient data between August 6 and August 8, 2024. Affected data includes names, addresses, medical record numbers, diagnoses, Social Security numbers, and prescription information. The company engaged forensic investigators, contained the incident, notified law enforcement, and is offering one year of credit monitoring to affected individuals.
Leak gap clock⏱ Leak >30d11 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_51267814e9f4f422HHS OCRfiled 2024-10-14(9d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-593770
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 23, 2024
- Raw hash
- 138ec5cd06aa66009f644c664d7d17844027c4324e1f2b708568b9c320941413
Reporting entity
- Name
- OnePoint Patient Carenorm: onepoint patient care
Victim entity
- Name
- OnePoint Patient Carenorm: onepoint patient care
Incident
- Discovered
- Aug 8, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.