HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPHIHEALTH_BASICMediumContained
Warren General Hospital
bd_1924dfe0062bd3f1 · schema v1 · pii pii-v1
Full breach record for Warren General Hospital →Warren General Hospital notified consumers of a data breach where an unknown actor accessed systems between Sept 15-23, 2023, downloading patient and employee data including names, SSNs, financial info, and medical records. WGH engaged cybersecurity specialists, reported to federal law enforcement and HHS, and offered credit monitoring.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by ransomhouse about this victim predates this filing by 55 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0093aa35975521dfNew Hampshire State AGfiled 2023-11-17Verified
- bd_d03a06da70bd116fHHS OCRfiled 2023-11-09(8d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-17-warren-general-hospital-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2023
- Raw hash
- fde867cb9ddcdc10aaf8cedee40f4b3e3a778325717485d6f1050defc53f2b30
Reporting entity
- Name
- Warren General Hospitalnorm: warren general hospital
- Domain
- wgh.org
Victim entity
- Name
- Warren General Hospitalnorm: warren general hospital
- Domain
- wgh.org
Incident
- Discovered
- Sep 24, 2023
- Materiality determined
- —
- Notification sent
- Nov 17, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the event to federal law enforcementreported the event to U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.