DisclosureLens
HackingHealthcareHealthcareVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)LowContained

The Harris Center for Mental Health and IDD

bd_66f6b8de416d0d7f · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 23, 2023

Filed

Sep 25, 2023

To disclose

13 weeks

Affected

5state residents only

Linked

4 filings

Confidence

66%
Full breach record for The Harris Center for Mental Health and IDD5 incidents on file

The Harris Center for Mental Health and IDD notified individuals of a data breach involving a third-party service provider's use of MOVEit file transfer software. Unauthorized parties exploited a previously unknown vulnerability (zero-day) in MOVEit starting late May 2023. The Harris Center learned of the compromise on June 23, 2023. The breach exposed names and other personal information. The organization offered one year of identity protection services.

Incident timeline

undetected · 23 days
discovery → filing · 13 weeks / 94 days

May 31, 2023

Begins

Jun 23, 2023

Discovered

Sep 25, 2023

Filed

vs. sector median

+2 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
New Hampshire State AGSep 25 · first
Massachusetts State AGSep 25 · first
Maine State AGSep 25 · first
Montana State AGSep 25 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.