MalwareRansomwareData EncryptedEmployee Data InvolvedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICEMPLOYMENTLowContained
Prestige Care, Inc.
bd_e741fee000231657 · schema v1 · pii pii-v1
Full breach record for Prestige Care, Inc. →Prestige Care, Inc. experienced a malware incident on September 7, 2023, which prevented access to certain files. An unauthorized actor may have accessed systems storing personal and health information of current/former employees and residents. The company launched an investigation, confirmed system security, and is offering 12 months of credit monitoring. No evidence of identity theft or fraud was found.
California clockDiscovered Sep 7, 2023 → Notified Mar 11, 2024186d ✗ CA 60-day late27 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3880b3e3c4552950Maine State AGfiled 2024-01-31(40d gap)Candidate
- bd_4cc2c2364289132fWashington State AGfiled 2024-01-31(40d gap)Verified
- bd_5862171e440bd209California State AGfiled 2024-01-31(40d gap)Verified
- bd_723344339b1fe3cbIndiana State AGfiled 2024-01-31(40d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 40d gap
- bd_b1727ba2ad3f8ecdMontana State AGfiled 2024-01-31(40d gap)Verified
- bd_c30260d39aaac1cdNew Hampshire State AGfiled 2024-01-31(40d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582272
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2024
- Raw hash
- ab253119e084ded57241c2619b06ceec56d7ceda9ab0fff9273ff9ca5d840c38
Reporting entity
- Name
- Prestige Care, Inc.norm: prestige care
- Domain
- prestigecare.com
Victim entity
- Name
- Prestige Care, Inc.norm: prestige care
- Domain
- prestigecare.com
Incident
- Discovered
- Sep 7, 2023
- Materiality determined
- —
- Notification sent
- Mar 11, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Notified applicable regulatory authorities, as required by law
Compliance
- Time to disclose
- 27 weeks(186 days from discovery to filing)
- Compliance flags
- CA 60-day late · 186d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 7, 2023→ Notified: Mar 11, 2024186d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.