Social EngineeringPhishingTargetedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Beaver Medical Group (BMG) / Epic Management LLC (EPIC)
bd_d6f4dce472358f95 · schema v1 · pii pii-v1
Full breach record for Beaver Medical Group (BMG) / Epic Management LLC (EPIC) →On January 24, 2023, Beaver Medical Group (BMG) / Epic Management LLC (EPIC), part of Optum, detected unusual activity on an employee workstation. An unauthorized third party launched a targeted phishing attack, gaining temporary access to certain emails and records. The incident involved names, member IDs, health plan names, and premium payment amounts. No SSNs, clinical info, or financial account data were compromised. Security controls were enhanced.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564084
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2023
- Raw hash
- ade2c6e27ca7179fbcaaaedcfd9530ff9814de2ed45e9f3af541ed75c98b9d39
Reporting entity
- Name
- Epicnorm: epic
- Domain
- getepic.com
Victim entity
- Name
- Beaver Medical Group (BMG) / Epic Management LLC (EPIC)norm: beaver medical group bmg epic management llc epic
Incident
- Discovered
- Jan 24, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.