HackingData ExfiltratedIDENTITY_BASICHEALTH_BASICPHILowActive
The Brien Center for Mental Health and Substance Abuse Services
bd_06ad8d28367fc027 · schema v1 · pii pii-v1
Full breach record for The Brien Center for Mental Health and Substance Abuse Services →The Brien Center for Mental Health and Substance Abuse Services, Inc. disclosed unauthorized access to its network between May 19-21, 2025. The incident may have exposed names, dates of birth, addresses, phone numbers, email addresses, client IDs, visit dates/times, and clinical diagnostic information. The investigation is ongoing. The organization engaged third-party cybersecurity specialists and is offering credit monitoring and identity restoration services to affected individuals.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ae763c930cd90ff1HHS OCRfiled 2025-07-18Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-18-brien-center-mental-health-and-substance-abuse-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 18, 2025
- Raw hash
- 4b353deec58745203113edda602d71b74cc6f5071f719c54797e7aad36990392
Reporting entity
- Name
- The Brien Center for Mental Health and Substance Abuse Servicesnorm: the brien center for mental health and substance abuse
Victim entity
- Name
- The Brien Center for Mental Health and Substance Abuse Servicesnorm: the brien center for mental health and substance abuse
Incident
- Discovered
- May 21, 2025
- Materiality determined
- —
- Notification sent
- Jul 18, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.