Sunrise Medical Laboratories, Inc. notified California regulators of a data security incident involving its third-party vendor, Retrieval Masters Creditors Bureau (d/b/a American Medical Collection Agency). The vendor's website payment page and database were compromised, potentially exposing patient names, addresses, dates of birth, and treatment information. Sunrise engaged cybersecurity experts, terminated the vendor relationship, and sent notification letters to affected individuals.