HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Sutter Senior Care
bd_21791ec6387ec632 · schema v1 · pii pii-v1
Full breach record for Sutter Senior Care →Sutter Senior Care PACE notified residents of a data breach involving their vendor, Cognisight, LLC. Cognisight was impacted by the global MOVEit exploit. On May 31, 2023, Sutter Senior Care learned of the incident. Forensic investigation confirmed files were taken from the MOVEit server. Affected data includes names, dates of birth, SSNs, and health information. Credit monitoring was provided.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_dbc20324d95e1c1cHHS OCRfiled 2023-07-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570696
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2023
- Raw hash
- 47657170e451927850a97f6065513fcac41e2d1854c9404bc8cc0ca83c4ea381
Reporting entity
- Name
- Cognisight LLCnorm: cognisight
Victim entity
- Name
- Sutter Senior Carenorm: sutter senior care
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Cognisight, LLC
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.