HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICLowContained
La Perouse, LLC
bd_d4eade49205a11ce · schema v1 · pii pii-v1
Full breach record for La Perouse, LLC →La Perouse LLC, a patient billing services provider, notified the California Attorney General of a data breach affecting patient information. On July 8, 2025, the company discovered unauthorized access to a third-party billing platform account. An attacker copied files containing names and other personal information. The breach window is May 27, 2025, to July 9, 2025. La Perouse engaged forensic investigators, secured its own networks, and implemented additional safeguards with the vendor. Affected individuals are offered 12 months of credit monitoring.
California clockDiscovered Jul 8, 2025 → Notified May 28, 2026324d ✗ CA 60-day late46 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3b7be1c9afbd45dbLeak Siteeverestfiled 2025-08-08(293d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_76f278da7c7bacd3HHS OCRfiled 2025-09-02(268d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624047
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2026
- Raw hash
- 7aba65b2b50dd871b273c15efa92d5f9f312a61401ee3b1b1c47b865250989fb
Reporting entity
- Name
- La Perouse, LLCnorm: la perouse
- Domain
- laperouse.us
Victim entity
- Name
- La Perouse, LLCnorm: la perouse
- Domain
- laperouse.us
Incident
- Discovered
- Jul 8, 2025
- Materiality determined
- —
- Notification sent
- May 28, 2026
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Third-party billing platform
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 46 weeks(324 days from discovery to filing)
- Compliance flags
- CA 60-day late · 324dLeak >180dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 8, 2025→ Notified: May 28, 2026324d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: May 28, 2026→ AG copy submitted: May 28, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.