HackingStolen CredentialsDelayed DiscoveryCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICPIILowContained
Regional Family Medicine
bd_59df8936e67f509a · schema v1 · pii pii-v1
Full breach record for Regional Family Medicine →Regional Family Medicine, a healthcare provider, notified consumers of a data breach where an unknown actor gained unauthorized access to its network between June 8 and June 26, 2023. The incident potentially exposed names and other personal information of patients and employees. The company engaged forensic experts, notified federal and state law enforcement, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday24 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by karakurt about this victim predates this filing by 138 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_64d8657fa073e9ccLeak Sitekarakurtfiled 2023-07-28(138d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_491d22c0a5773065Montana State AGfiled 2023-12-12(1d gap)Verified by operator
- bd_9f232a4b4162f11cMaine State AGfiled 2023-12-12(1d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-13-regional-family-medicine-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 13, 2023
- Raw hash
- cd7c896f076d95a57e47bf71c10fb663be3346d53db452924632fc74bece40dc
Reporting entity
- Name
- Regional Family Medicinenorm: regional family medicine
Victim entity
- Name
- Regional Family Medicinenorm: regional family medicine
Incident
- Discovered
- Jun 26, 2023
- Materiality determined
- Oct 13, 2023
- Notification sent
- Dec 12, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of InvestigationNotified Homeland SecurityNotified Arkansas State Police
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(170 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.