HackingSupply Chain (3P Vendor)Customer Data InvolvedData DestroyedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIALMediumContained
Eye Care Leaders
bd_f172872cc498a4c4 · schema v1 · pii pii-v1
Full breach record for Eye Care Leaders →Wolfe Clinic, P.C. notified patients that their data may have been exposed due to a security incident at their third-party vendor, Eye Care Leaders, on December 4, 2021. An unauthorized party accessed the myCare Integrity platform and deleted databases and system configuration files. Eye Care Leaders stopped the access immediately. While there was no evidence that Wolfe Clinic's patient records were accessed, the possibility of exposure of PHI and PII (including SSNs) could not be ruled out. Identity monitoring services were offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557367
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2022
- Raw hash
- ea5c4c528ebe852ef51bfb62079f8dd34c002938bcf3bc370b5b8d4cf7e9bf62
Reporting entity
- Name
- Wolfe Clinicnorm: wolfe clinic
Victim entity
- Name
- Eye Care Leadersnorm: eye care leaders
Incident
- Discovered
- Dec 4, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1485 Data Destruction
- Threat actor
- External
- Third party
- via Eye Care Leaders
Compliance
- Time to disclose
- 41 weeks(289 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.