HackingDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Bay Cove Human Services, Inc.
bd_79885ea9c07889f5 · schema v1 · pii pii-v1
Full breach record for Bay Cove Human Services, Inc. →Bay Cove Human Services, Inc. notified clients and employees of a data security incident discovered on December 30, 2024. Unauthorized access to network systems occurred, potentially exposing personal and protected health information. Specific data types were not identified during the investigation. Bay Cove engaged cybersecurity experts, secured systems, and offered 12 months of credit monitoring and identity protection services through IDX.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_276c429fca980a62HHS OCRfiled 2025-03-03Verified
- bd_d999f6aae5ecda38Indiana State AGfiled 2025-03-03Verified
- bd_e1baf59f2f15c475Maryland State AGfiled 2025-03-03Verified
- bd_354b3be519e69893Maine State AGfiled 2025-03-04(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_97d3b4169cd24946New Hampshire State AGfiled 2025-03-04(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-03-bay-cove-human-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2025
- Raw hash
- 8fa882fe7c65e5e23ff3c01601a0f7e540b81931e262476bcf897dbfbc629c3f
Reporting entity
- Name
- Bay Cove Human Services, Inc.norm: bay cove human
Victim entity
- Name
- Bay Cove Human Services, Inc.norm: bay cove human
Incident
- Discovered
- Dec 30, 2024
- Materiality determined
- —
- Notification sent
- Mar 3, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.