HackingStolen CredentialsCustomer Data InvolvedPHIIDENTITY_BASICLowContained
OPTION CARE HEALTH, INC.
bd_ed4b9a2c5fb649a5 · schema v1 · pii pii-v1
Full breach record for OPTION CARE HEALTH, INC. →Option Care Health notified patients that an unknown party briefly accessed an employee's email inbox on July 31, 2024. The company became aware of the issue on August 1, 2024, and terminated access. Forensic analysis determined that Protected Health Information (PHI) and basic identity information may have been impacted. The company reset passwords, restricted access, and engaged Kroll for identity monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_567eeed2e6920dbfHHS OCRfiled 2024-11-15Verified
- bd_b948d8241cfd63f1Montana State AGfiled 2024-11-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-594993
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2024
- Raw hash
- ec7face8e8751b894cc5841d19ddcbca9a8a263a741b5a28650cd5db93482bcb
Reporting entity
- Name
- OPTION CARE HEALTH, INC.norm: option care health
- Domain
- optioncare.com
Victim entity
- Name
- OPTION CARE HEALTH, INC.norm: option care health
- Domain
- optioncare.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.