Skip to content

CBLPath

Disclosed Jul 15, 20197 years ago141,956 affectedConfirmed

Official notice

CBLPath, Inc., the covered entity (CE), reported that its business associate (BA), Retrieval-Masters Creditors Bureau, Inc., doing business as American Medical Collection Agency, was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of 141,956 individuals. The ePHI involved included names, addresses, phone numbers, dates of service, birthdates, clinical information, and financial information. The CE notified HHS, affected individuals, and the media. As a result of OCR’s investigation, the CE implemented additional administrative safeguards to better protect its sensitive data. As a consequence of this breach incident, the CE terminated its business relationship with the BA.

What is known

People affected141,956 (as reported to HHS)
DisclosedJul 15, 2019
HappenedAug 1, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: CBLPathoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): CBLPath (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAJul 15, 2019
HHS archivetotalJul 15, 2019141,956
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 141956 · backfill source
  • 2026-09-25 · summary: empty to CBLPath, Inc., the covered entity (CE), reported that its business associate (BA), Retrieval-Masters Creditors Bureau, Inc., doing business as American Medical Collection Agency, was the victim of a cyber-attack that affected the electronic · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about CBLPath

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.