HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Maxim
bd_df999b80ae34a55f · schema v1 · pii pii-v1
Full breach record for Maxim →Maxim Healthcare Group experienced unauthorized access to employee email accounts between October 1, 2020, and December 4, 2020. The incident involved the compromise of valid credentials, leading to the collection of email data. The breach potentially exposed personal information, including names, addresses, and government identifiers, affecting 88 Rhode Island residents. Maxim implemented MFA, engaged a new Security Operations Center, and offered 12 months of credit monitoring.
California clockDiscovered Dec 4, 2020 → Notified Sep 21, 2021291d ✗ CA 60-day late48 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c13dda61b3242547Montana State AGfiled 2021-11-04Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547204
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2021
- Raw hash
- 0d947c26924b297e469d3cf40eb2b0a8498858dba2a4c075b087cc155a9a3184
Reporting entity
- Name
- Maximnorm: maxim
- Domain
- maxim.com
Victim entity
- Name
- Maximnorm: maxim
- Domain
- maxim.com
Incident
- Discovered
- Dec 4, 2020
- Materiality determined
- —
- Notification sent
- Sep 21, 2021
- Affected individuals
- 88
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Maxim Healthcare is notifying relevant state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 48 weeks(335 days from discovery to filing)
- Compliance flags
- CA 60-day late · 291d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 4, 2020→ Notified: Sep 21, 2021291d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.