DisclosureLens
HackingHealthcareHealthcareStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Self Regional Healthcare

bd_4223f24fcb92d75c · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 28, 2024

Filed

Jul 24, 2024

To disclose

8 weeks

Affected

Not disclosed

Confidence

67%
Full breach record for Self Regional Healthcare5 incidents on file

Self Regional Healthcare notified consumers of a data breach involving third-party vendor Medibase Group, Inc. Unauthorized access occurred around Jan 26, 2024, discovered May 28, 2024. Affected data included names, SSNs, DOBs, and financial balances. No clinical data was impacted. Medibase engaged forensic investigators and reported to federal law enforcement. Affected individuals offered credit monitoring.

Vermont clock VT AG >14 bday8 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 123 days
discovery → filing · 8 weeks / 57 days

Jan 26, 2024

Begins

May 28, 2024

Discovered

Jul 24, 2024

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.