PACIFIC HEIGHTS ASSET MANAGEMENT, LLC

PACIFIC HEIGHTS ASSET MANAGEMENT, LLC

A potential data security incident has resulted in the inadvertent exposure of some patients’ personal and health insurance information.

Although at this time there is no evidence that patients’ information was actually compromised or not but Ms. Bowden, a board licensed acupuncturist has taken steps to notify any patients who may have been affected by this incident.

This includes sending letters to anyone whose information might have been exposed.

Ms. Bowden discovered that her Pacific Heights office had been burglarized and a computer was stolen.

Although the computer was password protected, it contained patients’ names, addresses, contact information, dates of service, and diagnosis codes.

Social Security Numbers or financial/billing information was not involved in this incident.

Source: https://www.databreaches.net/san-francisco-acupuncturist-notifies-patients-whose-records-were-stolen-in-burglary/

TPRM report: https://scoringcyber.rankiteo.com/company/pacific-heights-asset-management-llc

"id": "pac1239822",
"linkid": "pacific-heights-asset-management-llc",
"type": "Vulnerability",
"date": "06/2018",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'location': 'Pacific Heights',
                        'name': "Ms. Bowden's Practice",
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Physical Theft',
 'customer_advisories': ['Letters to affected patients'],
 'data_breach': {'personally_identifiable_information': ['Names',
                                                         'Addresses',
                                                         'Contact information'],
                 'sensitivity_of_data': 'Medium',
                 'type_of_data_compromised': ['Personal Information',
                                              'Health Information']},
 'description': 'A potential data security incident has resulted in the '
                'inadvertent exposure of some patients’ personal and health '
                'insurance information due to a burglary and theft of a '
                "computer from Ms. Bowden's Pacific Heights office.",
 'impact': {'data_compromised': ["Patients' names",
                                 'Addresses',
                                 'Contact information',
                                 'Dates of service',
                                 'Diagnosis codes'],
            'systems_affected': ['Computer']},
 'initial_access_broker': {'entry_point': 'Physical Access'},
 'motivation': 'Theft of Computer Equipment',
 'post_incident_analysis': {'root_causes': 'Physical Theft'},
 'response': {'communication_strategy': ['Sending letters to affected '
                                         'patients']},
 'threat_actor': 'Burglar',
 'title': 'Data Security Incident at Pacific Heights Office',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Physical Security'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.