HackingRansomwareVulnerability ExploitRansom DemandedData ExfiltratedData PublishedTargetedPHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PruittHealth Home
bd_67aab287e356a3cf · schema v1 · pii pii-v1
Full breach record for PruittHealth Home →PruittHealth notified consumers of a November 2023 cyber incident where illegal foreign actors attacked its network, potentially exfiltrating PHI, SSNs, and financial data. Hackers demanded ransom and threatened to publish data on the dark web. Forensic investigators were engaged. Exposure is unconfirmed but possible.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by noescape about this victim predates this filing by 196 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_670929f48b917eebLeak Sitenoescapefiled 2023-11-17(196d gap)Verified by operator
Regulatory filings (1) · sorted by filing gap
- bd_683938f1d7b9859bNew Hampshire State AGfiled 2024-06-06(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-31-pruitthealth-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2024
- Raw hash
- 833214a5c7d821c58c0d9d9abb7b49698f985814f02a31e9a7adc49389a62e7c
Reporting entity
- Name
- PruittHealth Homenorm: pruitthealth home
- Domain
- pruitthealth.com
Victim entity
- Name
- PruittHealth Homenorm: pruitthealth home
- Domain
- pruitthealth.com
Incident
- Discovered
- Nov 1, 2023
- Materiality determined
- May 31, 2024
- Notification sent
- May 31, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.