HackingStolen CredentialsCapture Stored DataDelayed DiscoveryCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
SYNERGY HomeCare
bd_4924a611ea1ef2aa · schema v1 · pii pii-v1
Full breach record for SYNERGY HomeCare →Synergy Healthcare Services notified consumers of a December 2022 unauthorized network access incident affecting PHI and PII (SSN, DL, bank accounts) of patients from affiliated care centers. The breach was discovered in early December 2022, investigated by third-party experts, and notification was sent in July 2023. No fraudulent use suspected. Credit monitoring offered.
Vermont clock✗ VT AG >45 bday34 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5257e9b6b57e9079Montana State AGfiled 2023-07-26(1d gap)Candidate
- bd_1664820794ed528eMaine State AGfiled 2023-07-31(4d gap)Candidate
- bd_60b196394ca9f99cHHS OCRfiled 2023-07-31(4d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-27-synergy-healthcare-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- e629a372fa6f390988c11eddfad665e3b772cf01f0854ba87737ec9db50ed90b
Reporting entity
- Name
- SYNERGY HomeCarenorm: synergy homecare
- Domain
- synergyhomecare.com
Victim entity
- Name
- SYNERGY HomeCarenorm: synergy homecare
- Domain
- synergyhomecare.com
Incident
- Discovered
- Dec 1, 2022
- Materiality determined
- Jul 27, 2023
- Notification sent
- Jul 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 34 weeks(238 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.