HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NextGen Healthcare, Inc.
bd_33ab8daf3c08c256 · schema v1 · pii pii-v1
Full breach record for NextGen Healthcare, Inc. →NextGen Healthcare, Inc. notified Vermont consumers of a data incident where an unknown third party gained unauthorized access to personal information (name, DOB, address, SSN) between March 29 and April 14, 2023. No health records were accessed. NextGen engaged forensic experts, reset passwords, contacted law enforcement, and offered 24 months of identity theft protection.
Vermont clock⏱ VT AG >14 bday28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_03d4dffa3da1766cMontana State AGfiled 2023-04-28(1d gap)Candidate
- bd_1c6d555d72e68d6fDelaware State AGfiled 2023-04-28(1d gap)Verified
- bd_7e4510c6361c4a71Washington State AGfiled 2023-05-03(6d gap)Verified
- bd_7a7f5ee7fb7c68c8Oregon State AGfiled 2023-05-04(7d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 8d gap
- bd_5e938c6c211b169dNew Hampshire State AGfiled 2023-05-05(8d gap)Verified
- bd_67403124c4531ddcMaine State AGfiled 2023-05-05(8d gap)Verified
- bd_f1137d837aea9e06California State AGfiled 2023-05-05(8d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-27-nextgen-healthcare-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2023
- Raw hash
- d0afa7dbd3d6cf4c905b7625b4362859120e898a129d382a2ccf5e7d48370359
Reporting entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Victim entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Incident
- Discovered
- Mar 30, 2023
- Materiality determined
- —
- Notification sent
- Apr 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- contacted law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.