MalwareRansomwareCapture Stored DataData EncryptedData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
AKUMIN OPERATING CORP.
bd_db7efd6c0c4d9e1a · schema v1 · pii pii-v1
Full breach record for AKUMIN OPERATING CORP. →Akumin, Inc., a healthcare imaging provider, experienced a ransomware incident on October 11, 2023. Malware locked access to computer files, and files were copied without permission. Affected data includes PHI, SSNs, and payment card information for patients and employees. Akumin contained the incident, took systems offline, and is providing credit monitoring.
California clockDiscovered Oct 11, 2023 → Notified Dec 23, 2024439d ✗ CA 60-day late15 months discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_31930fb683ccf8b8Montana State AGfiled 2024-12-23Candidate
- bd_647223fbc4b0f6c6Indiana State AGfiled 2024-12-23Verified
- bd_e16c383f2f31d772Washington State AGfiled 2024-12-23Verified
- bd_eb1cfb9c9e6261dcVermont State AGfiled 2024-12-23Verified
Show 1 more filing ↓Show fewer ↑
- bd_ee2355bc545555b4New Hampshire State AGfiled 2024-12-23Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-596613
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2024
- Raw hash
- 4b04e8d1fa8c19a03f4a16f53e26a77bca33fc49b0d7717ddd6ad82cfde20b69
Reporting entity
- Name
- AKUMIN OPERATING CORP.norm: akumin operating
Victim entity
- Name
- AKUMIN OPERATING CORP.norm: akumin operating
Incident
- Discovered
- Oct 11, 2023
- Materiality determined
- —
- Notification sent
- Dec 23, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified certain law enforcement and other governmental authorities
Compliance
- Time to disclose
- 15 months(439 days from discovery to filing)
- Compliance flags
- CA 60-day late · 439d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 11, 2023→ Notified: Dec 23, 2024439d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.