DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Government IDMediumContained

Tavistock

bd_5835db8962fcdd09 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 1, 2023

Filed

Jul 17, 2023

To disclose

7 weeks

Affected

2state residents only

Confidence

66%
Full breach record for Tavistock2 incidents on file

Tavistock Health Management Company, LLC reported a security incident involving its vendor, Vitality Group, LLC. Vitality's MOVEit file transfer software was exploited via a zero-day vulnerability on May 30, 2023. Vitality detected the vulnerability on June 1, 2023, and disconnected the server. The breach may have exposed personal information, including SSNs, of 2 New Hampshire residents. Notifications were sent on July 17, 2023, offering credit monitoring.

Leak gap clock Leak >180d7 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 2 days
discovery → filing · 7 weeks / 46 days

May 30, 2023

Begins

Jun 1, 2023

Discovered

Jul 17, 2023

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
A leak claim by cuba about this victim predates this filing by 461 days.View originating leak claim

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.