The Vitality Group
bd_448dd79b72caf880 · schema v1 · pii pii-v1
Full breach record for The Vitality Group →7 incidents on fileThe Vitality Group, LLC notified affected individuals of a data security incident involving the MOVEit file transfer program. The vulnerability allowed unauthorized access to a server on May 30, 2023. Exposed data included names, Social Security numbers, dates of birth, and wellness activity participation indicators. Vitality disconnected the server on June 1, 2023, and offered two years of credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jun 1, 2023
Discovered
Jul 17, 2023
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_26be677794ddc28b2023-07-17Verified
- New Hampshire State AGbd_ebfe3a7beed221c22023-07-18 · +1dVerified
- HHS OCRbd_bbec978895f7fbc72023-07-11 · +6dVerified
- Montana State AGbd_7380e4c0987b38262023-07-06 · +11dVerified
Show 1 more filing ↓Show fewer ↑up to 17d gap
- Maine State AGbd_04271a52b6c1bf452023-06-30 · +17dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Jun 30 (ME), last Jul 18 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.