MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
AKUMIN OPERATING CORP.
bd_eb1cfb9c9e6261dc · schema v1 · pii pii-v1
Full breach record for AKUMIN OPERATING CORP. →Akumin, Inc., a healthcare imaging provider, disclosed a ransomware incident occurring on October 11, 2023. Malware encrypted files and data was exfiltrated. Affected data included patient PII (SSN, DOB, medical records) and employee data (SSN, payment card info). The company took systems offline, engaged law enforcement, and is issuing rolling notifications. A specific count of 15,448 Rhode Island residents was noted.
Vermont clock✗ VT AG >45 bday15 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_31930fb683ccf8b8Montana State AGfiled 2024-12-23Candidate
- bd_647223fbc4b0f6c6Indiana State AGfiled 2024-12-23Verified
- bd_db7efd6c0c4d9e1aCalifornia State AGfiled 2024-12-23Verified
- bd_e16c383f2f31d772Washington State AGfiled 2024-12-23Verified
Show 1 more filing ↓Show fewer ↑
- bd_ee2355bc545555b4New Hampshire State AGfiled 2024-12-23Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-23-akumin-operating-corp-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2024
- Raw hash
- eeea07408f1961bae158406be9559e807ffdf2dd20062be6ddba3242d5abcf99
Reporting entity
- Name
- AKUMIN OPERATING CORP.norm: akumin operating
Victim entity
- Name
- AKUMIN OPERATING CORP.norm: akumin operating
Incident
- Discovered
- Oct 11, 2023
- Materiality determined
- —
- Notification sent
- Dec 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified certain law enforcement and other governmental authorities
Compliance
- Time to disclose
- 15 months(439 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.