DisclosureLens
HackingHealthcareHealthcareVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIGovernment IDIdentity (basic)Health (basic)MediumContained

Sutter Senior Care PACE

bd_21791ec6387ec632 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Jul 22, 2023

To disclose

7 weeks

Affected

Not disclosed

Confidence

66%
Full breach record for Sutter Senior Care PACE

Sutter Senior Care PACE notified residents of a data breach involving their vendor, Cognisight, LLC. Cognisight was impacted by the global MOVEit exploit. On May 31, 2023, Sutter Senior Care learned of the incident. Forensic investigation confirmed files were taken from the MOVEit server. Affected data includes names, dates of birth, SSNs, and health information. Credit monitoring was provided.

Incident timeline

undetected · 3 days
discovery → filing · 7 weeks / 52 days

May 28, 2023

Begins

May 31, 2023

Discovered

Jul 22, 2023

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.