HackingDelayed DiscoveryIDENTITY_BASICLowContained
Carolina Arthritis
bd_5c4c73fe34204471 · schema v1 · pii pii-v1
Full breach record for Carolina Arthritis →Carolina Arthritis Associates notified Vermont AG of a data security incident on Sept 27, 2024, involving unauthorized acquisition of files containing patient names. The organization engaged forensic experts, reported to the FBI, and provided 12 months of credit monitoring and identity protection services to affected individuals.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
A leak claim by threeam about this victim predates this filing by 125 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_afad31b5e423fe58Leak Sitethreeamfiled 2024-10-24(125d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_25b183630cee6006New Hampshire State AGfiled 2025-02-27Verified
- bd_3e3faec2dc9622c0Maine State AGfiled 2025-02-27Verified
- bd_47d1979d018b1d02HHS OCRfiled 2025-02-27Verified
- bd_7f5415b879da3317Indiana State AGfiled 2025-02-27Verified
Show 1 more filing ↓Show fewer ↑
- bd_8076b43f1a07995dMaryland State AGfiled 2025-02-27Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-27-carolina-arthritis-associates-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- 45734faa562474365fb8f3838de2f78bc78f4636b21b714759acf4295b98c1f5
Reporting entity
- Name
- Carolina Arthritisnorm: carolina arthritis
- Domain
- carolinaarthritis.com
Victim entity
- Name
- Carolina Arthritisnorm: carolina arthritis
- Domain
- carolinaarthritis.com
Incident
- Discovered
- Sep 27, 2024
- Materiality determined
- —
- Notification sent
- Feb 27, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to the FBI
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.