DisclosureLens
HackingProfessional ServicesHealthcareProfessional ServicesVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)PHIMediumContained

CHSPSC, LLC

bd_48a8fadad9619710 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 2, 2023

Filed

Mar 13, 2023

To disclose

6 weeks

Affected

657state residents only

Confidence

64%
Full breach record for CHSPSC, LLC7 incidents on file

CHSPSC, LLC notified South Carolina residents of a third-party security incident involving vendor Fortra, LLC. Fortra's GoAnywhere file transfer platform was compromised via a previously unknown vulnerability (zero-day) between Jan 28-30, 2023. Disclosed data included names, addresses, SSNs, DOBs, and medical/billing info for patients, employees, and others. CHSPSC engaged the FBI and CISA, patched systems, and offered 24 months of credit monitoring.

Incident timeline

undetected · 5 days
discovery → filing · 6 weeks / 39 days

Jan 28, 2023

Begins

Feb 2, 2023

Discovered

Mar 13, 2023

Filed

vs. sector median

12 wks faster

Part of FORTRA, LLC supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed657 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.