Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICCREDENTIALSLowContained
Partners in Pediatrics, P.C.
bd_59d7e8a4b02a6da7 · schema v1 · pii pii-v1
Full breach record for Partners in Pediatrics, P.C. →Partners in Pediatrics, P.C. reported a data security incident involving unauthorized access to a PIP email account in March 2025. The incident was limited to email content and did not involve electronic health records. Potentially affected information includes names and other PII. No evidence of misuse was found.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7310479be5d9b2e8Montana State AGfiled 2025-10-03Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-03-partners-pediatrics-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2025
- Raw hash
- d46228d47b441bc719d6ef83ac65f018d64701b0979133f18c9edbadcb2b2919
Reporting entity
- Name
- Partners in Pediatrics, P.C.norm: partners in pediatrics
Victim entity
- Name
- Partners in Pediatrics, P.C.norm: partners in pediatrics
Incident
- Discovered
- Mar 5, 2025
- Materiality determined
- Oct 3, 2025
- Notification sent
- Oct 3, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.