TRINITY HEALTH CORPORATION
bd_4c49d240e8481b68 · schema v1 · pii pii-v1
Full breach record for TRINITY HEALTH CORPORATION →Trinity Health, a multi-institutional Catholic health care system, disclosed a security incident involving its third-party vendor, Accellion. On January 29, 2021, Accellion notified Trinity Health of a flaw in its File Transfer Appliance. An unknown user exploited this vulnerability to download files containing protected health information (PHI), including patient names, addresses, dates of birth, medical record numbers, and financial data. Trinity Health took the appliance offline, launched an investigation, and offered one year of complimentary credit monitoring and identity theft restoration services to affected patients.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7e00641b86d5c465Maine State AGfiled 2021-04-05Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539704
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2021
- Raw hash
- 8e37778b2145140d17ff603a51b36f820605a23663bf50bbf6ad931000d30886
Reporting entity
- Name
- TRINITY HEALTH CORPORATIONnorm: trinity health
- Domain
- trinity-health.org
Victim entity
- Name
- TRINITY HEALTH CORPORATIONnorm: trinity health
- Domain
- trinity-health.org
Incident
- Discovered
- Jan 29, 2021
- Materiality determined
- —
- Notification sent
- Jan 20, 2021
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.