HackingCustomer Data InvolvedPIIIDENTITY_BASICHighContained
Ravkoo
bd_e4f82f363cdb1218 · schema v1 · pii pii-v1
Full breach record for Ravkoo →Ravkoo, a healthcare entity based in Auburndale, Florida, reported an internal system breach occurring between September 27, 2021, and December 7, 2021. The incident affected 105,000 individuals, including 368 Maine residents. Notification was sent on January 3, 2022, offering 12 months of credit monitoring and identity theft protection via Kroll. The breach was described as an 'internal system breach' involving unauthorized access.
Maine clockDiscovered Sep 27, 2021 → Filed with AG Jan 5, 2022100d ✗ ME AG >90d14 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_e271be692c34e932Oregon State AGfiled 2022-01-05Verified
- bd_b1c21d4401605dcbSouth Carolina State AGfiled 2022-01-04(1d gap)Verified
- bd_4b4f4f311c81eaeeWashington State AGfiled 2022-01-03(2d gap)Candidate
- bd_d601b80a96140270California State AGfiled 2022-01-03(2d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 2d gap
- bd_d90f0cc5f913c2beNew Hampshire State AGfiled 2022-01-03(2d gap)Verified
- bd_e92fcd9fc02d394aMontana State AGfiled 2022-01-03(2d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/142a7ad5-bef3-40c5-ac1c-f24d64014174.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2022
- Raw hash
- 3bb328088caa08c2dc5a54df294f15b9c9edf8ad9ad5f6b44a37b8fca83b2b0e
Reporting entity
- Name
- Ravkoonorm: ravkoo
Victim entity
- Name
- Ravkoonorm: ravkoo
Incident
- Discovered
- Sep 27, 2021
- Materiality determined
- —
- Notification sent
- Jan 3, 2022
- Affected individuals
- 105,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- ME AG >90d · 100dME resident >60d · 98d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 27, 2021→ Filed with AG: Jan 5, 2022100d 90 days ME AG >90d Maine Discovered: Sep 27, 2021→ Notified: Jan 3, 202298d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.