MalwareRansomwareStolen CredentialsData EncryptedMulti-Stage ChainPIIPHIIDENTITY_BASICLowContained
Coastal Hospice
bd_5ced0bd3806c1b47 · schema v1 · pii pii-v1
Full breach record for Coastal Hospice →Coastal Hospice & Palliative Care experienced a ransomware incident on July 24, 2023, resulting in unauthorized access and encryption of files containing personal and protected health information. The organization engaged cybersecurity experts, notified the FBI, and offered 12 months of credit monitoring via Equifax to affected individuals.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_03e39b52a31cd9e6Indiana State AGfiled 2024-01-22Verified
- bd_2f965f119e2bb703Delaware State AGfiled 2024-01-22Candidate
- bd_80dc10db64cbad33Delaware State AGfiled 2024-01-22Candidate
- bd_398ce6ad535153b5New Hampshire State AGfiled 2024-01-24(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-22-coastal-hospice-palliative-care-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 22, 2024
- Raw hash
- e0b147fff808ba35919bffb4ca0465f8a6d73cd30bc88ad251334ff085ba7ab1
Reporting entity
- Name
- Coastal Hospicenorm: coastal hospice
- Domain
- coastalhospice.org
Victim entity
- Name
- Coastal Hospicenorm: coastal hospice
- Domain
- coastalhospice.org
Incident
- Discovered
- Jul 24, 2023
- Materiality determined
- —
- Notification sent
- Jan 22, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.