PracticeMax
ent_985bbf8f512812b9963beda0
Disclosures
14
State AG · HHS OCR · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
685,574
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PracticeMax
- Normalized
- practicemax— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- practicemax.com
Disclosure history (14)newest first
- Maine State AGas reporting2024-12-26
PracticeSuite, Inc. notified the Maine AG that a cybercriminal gained access to a server containing backup records for Texan ENT Specialists on Oct 11, 2024. The breach impacted 13,353 individuals, exposing PHI, SSNs, and financial data. PracticeSuite secured the environment, engaged external cybersecurity professionals, and offered 24 months of Experian credit monitoring to affected individuals.
- New Hampshire State AGas victim2022-06-14
PracticeMax filed a supplemental notice with the New Hampshire AG regarding a ransomware incident. Unauthorized access occurred April 17–May 5, 2021. Data potentially included names, SSNs, DOBs, and health info. 46 NH residents notified. PracticeMax engaged specialists, restored systems, and implemented additional security controls.
- South Carolina State AGas victim2022-06-10
PracticeMax, a business management and IT solutions provider, disclosed a ransomware incident affecting its network. Unauthorized access occurred from April 17 to May 5, 2021, involving encrypted data and potential exfiltration from one server and limited email accounts. Affected data included names, SSNs, DOBs, health info, and financial data. PracticeMax notified the FBI, regulators, and customers starting October 19, 2021.
- Maine State AGas victim2022-06-10
PracticeMax reported a data breach that occurred between April 17, 2021, and May 5, 2021, and was discovered on February 2, 2022. The breach affected 28 Maine residents, compromising their names and Social Security numbers. Written notifications were sent to the affected individuals on June 10, 2022. The specific cause of the breach was not detailed.
- California State AGas victim2022-06-10
PracticeMax, a healthcare IT solutions provider, experienced a ransomware attack resulting in unauthorized access to its network from April 17 to May 5, 2021. The company became aware of the incident on May 1, 2021. The attack involved encryption of data, unauthorized access to email accounts, and potential exfiltration of files. Affected data may include PHI, SSNs, and financial information. PracticeMax engaged forensic specialists, disconnected systems, and offered one year of identity monitoring via Kroll.
- Oregon State AGas victim2022-06-10
PracticeMax reported a data breach to the Oregon Attorney General. The breach was reported on 2022-06-10. The breach occurred during 4/17/2021 - 5/5/2021. The breach was discovered on 6/7/2022. 529,058 individuals were affected. Notice was sent on 6/10/2022.
- New Hampshire State AGas victim2022-03-07
PracticeMax, a business management and IT solutions company serving healthcare and insurance sectors, experienced a ransomware incident. Unauthorized access occurred between April 17 and May 5, 2021, discovered on May 1, 2021. Ransomware encrypted data; files may have been removed from a server and email accounts accessed. Data types included PHI, SSNs, and financial info. 5 New Hampshire residents affected. Notifications began October 2021. Systems disconnected and additional safeguards implemented.
- Montana State AGas victim2022-03-04
PracticeMax, a business management and IT solutions provider, disclosed a ransomware incident where unauthorized access occurred from April 17 to May 5, 2021. The attack encrypted data and potentially exfiltrated sensitive information including SSNs, health data, and credentials. PracticeMax detected the incident on May 1, 2021, engaged forensic specialists, notified the FBI and regulators, and began notifying affected individuals in October 2021.
- Maine State AGas victim2022-03-04
PracticeMax, a business services provider, reported a data breach involving ransomware and a business email compromise. The incident occurred between April 17, 2022, and May 5, 2022. The breach compromised the names and Social Security numbers of 165,698 individuals. The company notified the affected individuals on March 4, 2022. Notably, the reported discovery and notification dates precede the stated occurrence dates, suggesting a data entry error in the source filing.
- Massachusetts State AGas victim2022-03-04
PracticeMax reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-03-04. 2,040 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2022-03-04
PracticeMax reported a data breach to the Indiana Attorney General. The breach occurred on 2021-04-17 and was reported on 2022-03-04. 1,469 Indiana residents were affected. 165,698 individuals affected in total.
- Illinois State AGas victim2022-01-01
PRACTICEMAX filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-182). The register records the breach as discovered on April 17, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2021-10-19
PracticeMax Inc. experienced a ransomware attack between April 17 and May 5, 2021, discovered on May 1, 2021. The incident involved unauthorized access to a server containing Protected Health Information (PHI), including names, dates of birth, addresses, phone numbers, Social Security Numbers (for some individuals), Member IDs, and clinical data. PracticeMax engaged forensic investigators, notified law enforcement, and implemented system rebuilds and enhanced security controls. Affected individuals were offered 24 months of credit monitoring.
- ARIZONAHHS OCRas victim2021-06-30
PracticeMax, Inc. reported to HHS on 2021-06-30 a Hacking/IT Incident affecting 685,574 individuals. Breached information located on Network Server. The business associate was the victim of a ransomware attack affecting PHI including names, diagnoses, addresses, DOB, SSNs, and financial info. The BA notified HHS, individuals, and media, and implemented additional technical safeguards.