PracticeMax
ent_985bbf8f512812b9963beda0
Disclosures
12
State AG · HHS OCR · 7 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
685,574
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PracticeMax
- Normalized
- practicemax— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- practicemax.com
Disclosure history (12)newest first
- 🦞Maine State AGas victim2024-12-26
PracticeSuite, Inc., a healthcare organization, reported a data breach discovered on October 18, 2024. The breach occurred on October 11, 2024, and affected one resident of Maine. The company provided written notification to the affected individual on November 15, 2024, and offered two years of credit monitoring services through Experian. The specific nature of the breach was not detailed in the public notice.
- 🦬Montana State AGas victim2023-09-13
PracticeSuite, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-13. The breach occurred from 6/19/2023 to 7/14/2023. 1 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2022-06-14
PracticeMax submitted a New Hampshire Attorney General breach notification on June 14, 2022. The incident involved unauthorized access to a database containing patient information, including names, dates of birth, and Social Security numbers. PracticeMax engaged forensic investigators and notified affected individuals. The incident is reported as contained.
- 🌴South Carolina State AGas victim2022-06-10
PracticeMax, a healthcare technology provider, disclosed a ransomware attack on April 17, 2021, affecting approximately 165,698 individuals. The incident involved the Medusa ransomware family, which encrypted patient data on a server and resulted in the exfiltration of sensitive information including names, Social Security numbers, and health records. Notifications were sent to the FBI, HHS, and affected individuals starting in October 2021, with written notices continuing through June 2022.
- 🦞Maine State AGas victim2022-06-10
PracticeMax reported a data breach that occurred between April 17, 2021, and May 5, 2021, and was discovered on February 2, 2022. The breach affected 28 Maine residents, compromising their names and Social Security numbers. Written notifications were sent to the affected individuals on June 10, 2022. The specific cause of the breach was not detailed.
- 🐻California State AGas victim2022-06-10
PracticeMax, a business management and IT solutions provider, disclosed a ransomware incident affecting its network from April 17, 2021, to May 5, 2021. The attack encrypted data and allowed unauthorized access to one server and limited email accounts. While no confirmed data disclosure was found, systems may have contained PII, PHI, SSNs, and financial data. PracticeMax disconnected systems, engaged forensic specialists, notified law enforcement, and offered one year of identity monitoring via Kroll.
- 🦫Oregon State AGas victim2022-06-10
PracticeMax reported a data breach to the Oregon Attorney General. The breach was reported on 2022-06-10. The breach occurred during 4/17/2021 - 5/5/2021. The breach was discovered on 6/7/2022. 529,058 individuals were affected. Notice was sent on 6/10/2022.
- 🦬Montana State AGas victim2022-03-04
PracticeMax reported a data breach to the Montana Attorney General. The breach was reported on 2022-03-04. The breach occurred on 5/1/2021. 145 Montana residents were affected.
- 🦞Maine State AGas victim2022-03-04
PracticeMax, a business services provider, reported a data breach involving ransomware and a business email compromise. The incident occurred between April 17, 2022, and May 5, 2022. The breach compromised the names and Social Security numbers of 165,698 individuals. The company notified the affected individuals on March 4, 2022. Notably, the reported discovery and notification dates precede the stated occurrence dates, suggesting a data entry error in the source filing.
- 🐻California State AGas victim2021-10-19
PracticeMax Inc. reported a ransomware attack on its network occurring between April 17, 2021, and May 5, 2021. The incident involved unauthorized access to a server containing Protected Health Information (PHI) and personally identifiable information (PII), including names, dates of birth, addresses, phone numbers, and Social Security Numbers for some individuals. PracticeMax engaged legal counsel and a forensic firm, restored system access, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring via Equifax. The breach impacted patients of DaVita's VillageHealth program.
- 🐻California State AGas victim2021-10-15
Anthem, Inc. reported a ransomware attack on its vendor, PracticeMax, affecting the VillageHealth program for End Stage Kidney Disease members. The breach occurred between April 17 and May 5, 2021, exposing PHI and basic PII (names, DOB, addresses, clinical data). PracticeMax engaged forensic investigators, notified law enforcement, and provided 24 months of credit monitoring.
- AZHHS OCRas victim2021-06-30
PracticeMax, Inc. reported to HHS on 2021-06-30 a Hacking/IT Incident affecting 685,574 individuals. Breached information located on Network Server. The business associate was the victim of a ransomware attack affecting PHI including names, diagnoses, addresses, DOB, SSNs, and financial info. The BA notified HHS, individuals, and media, and implemented additional technical safeguards.