MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Compass Behavioral Health
bd_225fc4e0b0d88793 · schema v1 · pii pii-v1
Full breach record for Compass Behavioral Health →Horizon Behavioral Health disclosed a ransomware incident discovered on March 16, 2025, with activity starting around March 13, 2025. The breach impacted patient demographic data (SSN, DL), clinical information, and insurance claims. Horizon engaged forensic experts, notified the FBI and CISA, and provided complimentary identity monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ba25fb5419d6a006Montana State AGfiled 2025-04-21Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-21-horizon-behavioral-health-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2025
- Raw hash
- 68d4a5fdc5aec9e349d718359fb18dd21c1181a74aeab065e9c46f3b1a01064e
Reporting entity
- Name
- Compass Behavioral Healthnorm: compass behavioral health
Victim entity
- Name
- Compass Behavioral Healthnorm: compass behavioral health
Incident
- Discovered
- Mar 16, 2025
- Materiality determined
- —
- Notification sent
- Apr 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state and federal law enforcement, including the FBI’s Cyber Crimes Division, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), and the Cyber Fusion Center of the Virginia State Police
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.