Discovery Practice Management, Inc.
ent_c4a55d5878b12d60c5686ccf
Disclosures
2
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
12,859
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Discovery Practice Management, Inc.
- Normalized
- discovery practice management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- California State AGas victim2021-07-01
Discovery Practice Management, Inc. experienced unauthorized access to staff email accounts for Authentic Recovery Center and Cliffside Malibu facilities between June 22 and June 26, 2020. The incident was discovered on July 31, 2020. Affected data may include names, addresses, dates of birth, SSNs, driver's license numbers, medical records, health insurance info, and financial account details. The company engaged forensic investigators, secured accounts, and offered one year of credit monitoring. The motive was believed to be payment diversion.
- CALIFORNIAHHS OCRas victim2021-06-05
Discovery Practice Management, Inc., a California-based business associate, reported to HHS on 2021-06-05 a ransomware attack affecting the PHI of 12,859 individuals. Breached information was located in Email systems. Exposed data included names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, diagnoses, prescription information, and health insurance and financial information. The BA notified HHS, affected individuals, and the media, and provided substitute notice. Mitigation included additional administrative and technical safeguards and staff retraining.