HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NextGen Healthcare, Inc.
bd_f1137d837aea9e06 · schema v1 · pii pii-v1
Full breach record for NextGen Healthcare, Inc. →NextGen Healthcare, Inc. notified individuals of a security incident where an unknown third party gained unauthorized access to personal information between March 29 and April 14, 2023. The accessed data included names, dates of birth, addresses, and Social Security numbers. No health or medical records were accessed. The company engaged forensic experts, reset passwords, and contacted law enforcement. Affected individuals are offered 24 months of identity theft protection.
California clockDiscovered Mar 30, 2023 → Notified Apr 28, 202329d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_5e938c6c211b169dNew Hampshire State AGfiled 2023-05-05Verified
- bd_67403124c4531ddcMaine State AGfiled 2023-05-05Verified
- bd_7a7f5ee7fb7c68c8Oregon State AGfiled 2023-05-04(1d gap)Verified
- bd_7e4510c6361c4a71Washington State AGfiled 2023-05-03(2d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 8d gap
- bd_03d4dffa3da1766cMontana State AGfiled 2023-04-28(7d gap)Candidate
- bd_1c6d555d72e68d6fDelaware State AGfiled 2023-04-28(7d gap)Verified
- bd_33ab8daf3c08c256Vermont State AGfiled 2023-04-27(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-566365
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2023
- Raw hash
- 29b98aef177de369c09c60a55e96c22bc88e805af6d243562fee28d6c7ad5168
Reporting entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Victim entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Incident
- Discovered
- Mar 30, 2023
- Materiality determined
- —
- Notification sent
- Apr 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Contacted law enforcement
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 30, 2023→ Notified: Apr 28, 202329d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.