HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Cornerstone Healthcare Group Management Services LLC
bd_28201747796ff006 · schema v1 · pii pii-v1
Full breach record for Cornerstone Healthcare Group Management Services LLC →Cornerstone Healthcare Group Management Services LLC disclosed a data breach occurring on December 19, 2023, involving unauthorized access to personal information of patients at supported healthcare facilities. The company engaged cybersecurity firms and law enforcement, and is offering credit monitoring services.
Vermont clock✗ VT AG >45 bday45 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_88a92967dc0456b4California State AGfiled 2024-11-02(1d gap)Candidate
- bd_3ea79518fc5ab9adNew Hampshire State AGfiled 2024-11-04(3d gap)Verified
- bd_5291e3d7b8c066a0New Hampshire State AGfiled 2024-11-06(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-01-cornerstone-healthcare-group-management-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2024
- Raw hash
- bb46ac2e665dd5c22ace327d577e655240146362b87f362044f09b3e6c813891
Reporting entity
- Name
- Cornerstone Healthcare Group Management Services LLCnorm: cornerstone healthcare group management
Victim entity
- Name
- Cornerstone Healthcare Group Management Services LLCnorm: cornerstone healthcare group management
Incident
- Discovered
- Dec 19, 2023
- Materiality determined
- —
- Notification sent
- Nov 1, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 45 weeks(318 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.