HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMINORMediumContained
Michigan Avenue Immediate Care
bd_ee4a03a44034b356 · schema v1 · pii pii-v1
Full breach record for Michigan Avenue Immediate Care →Michigan Avenue Immediate Care, a healthcare provider, disclosed a cybersecurity incident where an unauthorized third party gained access to its network on or around May 1, 2022. The breach affected patient records containing names, SSNs, dates of birth, driver's license numbers, and treatment/health insurance information. The company secured its network, retained forensic investigators, and offered complimentary credit monitoring and identity protection services to affected individuals, including minors.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_461c5e3ac0eb9651Maine State AGfiled 2022-06-30Verified
- bd_46ffb5a07fa7b176Oregon State AGfiled 2022-06-30Verified
- bd_7ad65124fdd32a4bHHS OCRfiled 2022-06-30Verified
- bd_7d1fbcc18ec50aa8California State AGfiled 2022-08-18(49d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 49d gap
- bd_ad4cab7e46c45393Maine State AGfiled 2022-08-18(49d gap)Verified
- bd_bcbfc45d63cad106Oregon State AGfiled 2022-08-18(49d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554783
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2022
- Raw hash
- e0b27b89d7074a955935a46d2dc4e454e235f4cb7c6d8c294970cc4a0a0b1470
Reporting entity
- Name
- Michigan Avenue Immediate Carenorm: michigan avenue immediate care
- Industry
- healthcare
Victim entity
- Name
- Michigan Avenue Immediate Carenorm: michigan avenue immediate care
- Industry
- healthcare
Incident
- Discovered
- May 1, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.