HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Columbus Regional Healthcare System, Inc.
bd_24d9b354b418af93 · schema v1 · pii pii-v1
Full breach record for Columbus Regional Healthcare System, Inc. →Columbus Regional Healthcare System notified consumers of a security incident where unauthorized access occurred between May 19-21, 2023. The investigation concluded on December 28, 2023, revealing that full names and government identifiers were removed from the network. One Rhode Island resident was explicitly identified as impacted. The organization engaged outside cybersecurity professionals and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday35 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by daixin about this victim predates this filing by 223 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_2fcfec8fdffc8f54Leak Sitedaixinfiled 2023-06-09(223d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_4e70fe80e3508930Maine State AGfiled 2024-01-19Verified
- bd_8852302e7d95aeedHHS OCRfiled 2024-01-19Verified
- bd_545284449387bb15New Hampshire State AGfiled 2024-01-24(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-19-columbus-regional-healthcare-system-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2024
- Raw hash
- 80f5de36c869471863dc004c52b72e71853158e96becb23b61b5194c525c3877
Reporting entity
- Name
- Columbus Regional Healthcare System, Inc.norm: columbus regional healthcare system
- Domain
- crhealthcare.org
Victim entity
- Name
- Columbus Regional Healthcare System, Inc.norm: columbus regional healthcare system
- Domain
- crhealthcare.org
Incident
- Discovered
- May 19, 2023
- Materiality determined
- —
- Notification sent
- Jan 19, 2024
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 35 weeks(245 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.