Discovery Practice Management, Inc.
ent_c4a55d5878b12d60c5686ccf
Disclosures
2
State AG · HHS OCR · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
12,859
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Discovery Practice Management, Inc.
- Normalized
- discovery practice management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- 🐻California State AGas victim2021-07-01
Discovery Practice Management, Inc. reported unauthorized access to staff email accounts between June 22-26, 2020, discovered on July 31, 2020. The breach potentially exposed patient and employee PII, including names, SSNs, DOBs, medical records, and financial data. Discovery engaged forensic investigators, secured accounts, and offered one year of credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas victim2021-06-05
Discovery Practice Management, Inc., a California-based business associate, reported to HHS on 2021-06-05 a ransomware attack affecting the PHI of 12,859 individuals. Breached information was located in Email systems. Exposed data included names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, diagnoses, prescription information, and health insurance and financial information. The BA notified HHS, affected individuals, and the media, and provided substitute notice. Mitigation included additional administrative and technical safeguards and staff retraining.