Social EngineeringPhishingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
CHARLESTON AREA MEDICAL CENTER, INC.
bd_1163f5e8b9d89d32 · schema v1 · pii pii-v1
Full breach record for CHARLESTON AREA MEDICAL CENTER, INC. →Charleston Area Medical Center notified Vermont AG of a phishing incident discovered Oct 2, 2024. An unauthorized party accessed a single user's email mailbox between Oct 2-3, 2024. Impacted data included names, DOB, driver's license, health info, and insurance info. CAMC engaged forensic experts, provided phishing training, enhanced safeguards, and offered 24 months of identity theft protection.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_198b717e5ee299f3HHS OCRfiled 2025-02-14Verified
- bd_2ef6dace0c02137dIndiana State AGfiled 2025-02-14Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-14-charleston-area-medical-center-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2025
- Raw hash
- 58e56d080ba60872642bd17b74fdd900fa9bab8763a9821bbc87ec790a813162
Reporting entity
- Name
- CHARLESTON AREA MEDICAL CENTER, INC.norm: charleston area medical center
Victim entity
- Name
- CHARLESTON AREA MEDICAL CENTER, INC.norm: charleston area medical center
Incident
- Discovered
- Oct 2, 2024
- Materiality determined
- Feb 14, 2025
- Notification sent
- Feb 14, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.