CHSPSC, LLC - Updated
bd_0d9ab92e55f3d8a0 · schema v1 · pii pii-v1
Full breach record for CHSPSC, LLC - Updated →CHSPSC, LLC disclosed a third-party security incident involving vendor Fortra, LLC. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of personal information for CHSPSC affiliates, including patients and employees. Affected data included names, addresses, medical billing/insurance info, diagnoses, medications, dates of birth, and Social Security numbers. Fortra contained the incident on January 31, 2023. CHSPSC notified law enforcement (FBI, CISA) and is offering 24 months of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_2b73da2633a307ffOregon State AGfiled 2023-03-07Verified
- bd_ee40a8445255d063Washington State AGfiled 2023-03-07Verified
- bd_8d82685405a418fcMontana State AGfiled 2023-03-08(1d gap)Verified
- bd_e8298cc5c3b2011eMaine State AGfiled 2023-03-08(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 41d gap
- bd_05ff925166a4537fOregon State AGfiled 2023-04-17(41d gap)Verified
- bd_bf411ffed68cd2ceCalifornia State AGfiled 2023-04-17(41d gap)Verified
- bd_fefafc85063dc9bbMaine State AGfiled 2023-04-17(41d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564032
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 7, 2023
- Raw hash
- 6f0680ce7add6f0595e262dcf9d92dff5e69d165e36bcec6490ec266cbe52433
Reporting entity
- Name
- CHSPSC, LLC - Updatednorm: chspsc llc updated
Victim entity
- Name
- CHSPSC, LLC - Updatednorm: chspsc llc updated
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified law enforcement, including the FBI and CISA
- Third party
- via Fortra, LLC
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.