DisclosureLens
AccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Northern Counties Health Care

bd_3176ee1578607fa7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 22, 2023

Filed

Sep 22, 2023

To disclose

≤1 day

Affected

Not disclosed

Confidence

67%
Full breach record for Northern Counties Health Care

Northern Counties Health Care, a Vermont healthcare provider, notified consumers on September 22, 2023, that on September 19, 2023, an email containing personal information was mistakenly sent to an individual instead of Blue Cross/Blue Shield during new employee medical insurance enrollment. The disclosed data included names, addresses, SSNs, dates of birth, and banking information. The organization attempted to recall the email and contacted the recipient to delete it. Affected individuals were advised to place fraud alerts and were offered one year of credit monitoring.

Vermont clock VT AG ≤14 bday≤1 day discovery → filing
notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

undetected · 3 days
discovery → filing · ≤1 day / 0 days

Sep 19, 2023

Begins

Sep 22, 2023

Discovered

Sep 22, 2023

Filed

vs. sector median

13 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.