HackingData ExfiltratedIDENTITY_BASICPHIHEALTH_BASICLowContained
Western Montana Mental Health Center
bd_48f24baf2ecae00e · schema v1 · pii pii-v1
Full breach record for Western Montana Mental Health Center →Western Montana Mental Health Center notified consumers of a data security incident discovered on September 15, 2024. Unauthorized access to files containing personal and protected health information (PHI) and names was confirmed. The organization engaged cybersecurity experts, notified the FBI, and offered complimentary identity protection services. No evidence of misuse was found. The specific number of affected individuals was not disclosed in the notice.
Vermont clock✗ VT AG >45 bday44 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_302a8478f032d5e0Montana State AGfiled 2025-07-17Candidate
- bd_6ec13e1ebb9b4d08Indiana State AGfiled 2025-07-17Verified
- bd_154ae35704eb4331Maine State AGfiled 2025-07-18(1d gap)Verified by operator
- bd_c165bdbada433eaeNew Hampshire State AGfiled 2025-07-18(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-17-western-montana-mental-health-center-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2025
- Raw hash
- dddc2393d9708706265e649395c52598389cffdf601f9a9e723a12dd0744eec9
Reporting entity
- Name
- Western Montana Mental Health Centernorm: western montana mental health center
Victim entity
- Name
- Western Montana Mental Health Centernorm: western montana mental health center
Incident
- Discovered
- Sep 15, 2024
- Materiality determined
- —
- Notification sent
- Jul 17, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 44 weeks(305 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.