DisclosureLens
HackingHealthcareHealthcareVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDMediumContained

AltaMed Health Services Corporation

bd_f20b0d4b99035379 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 1, 2023

Filed

Jun 29, 2023

To disclose

28 days

Affected

Not disclosed

Linked

2 filings

Confidence

64%
Full breach record for AltaMed Health Services Corporation →9 incidents on file

AltaMed Health Services Corporation notified the California AG of a data breach involving its third-party vendor, Vitality Group. The incident stemmed from a vulnerability in the MOVEit file transfer program exploited on May 30, 2023. Vitality identified the risk on June 1, 2023, and disconnected the server. Affected data included names, addresses, dates of birth, email addresses, and Social Security numbers. AltaMed is offering two years of credit monitoring to affected members.

California clockDiscovered Jun 1, 2023 → Notified Jun 28, 202326d ✓ CA 60-day OK28 days discovery → filing

Incident timeline

undetected · 2 days
discovery → filing · 28 days

May 30, 2023

Begins

Jun 1, 2023

Discovered

Jun 29, 2023

Filed

vs. sector median

6 wks faster

This filing is one of 2 filings about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
California State AGJun 29 · first · this page

Pattern: first filing Jun 29 (CA), last Aug 4 (CA) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.