HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Health Care and Rehabilitation Services of Southeastern Vermont, Inc.
bd_70a94fe33c8d5781 · schema v1 · pii pii-v1
Full breach record for Health Care and Rehabilitation Services of Southeastern Vermont, Inc. →Health Care and Rehabilitation Services of Southeastern Vermont, Inc. (HCRS) disclosed that unauthorized access occurred to two email accounts between Dec 4-9, 2024. The incident was identified on Dec 20, 2024. The unauthorized party accessed emails and files containing full names and other personal information. HCRS reset passwords and engaged outside cybersecurity professionals. The organization is offering complimentary credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ad2c7c9aae377c3fNew Hampshire State AGfiled 2025-08-04(4d gap)Verified
- bd_aa10c82806c65eebNew Hampshire State AGfiled 2025-06-23(38d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-31-health-care-and-rehabilitation-services-se-vermont-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2025
- Raw hash
- c2ddc23779df86deac121ef6181ce9203447965216cbd80d6702f4eabf843359
Reporting entity
- Name
- Health Care and Rehabilitation Services of Southeastern Vermont, Inc.norm: health care and rehabilitation services of southeastern vermont
Victim entity
- Name
- Health Care and Rehabilitation Services of Southeastern Vermont, Inc.norm: health care and rehabilitation services of southeastern vermont
Incident
- Discovered
- Dec 20, 2024
- Materiality determined
- —
- Notification sent
- Jul 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(223 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.