Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICMediumContained
The Mount Kisco Surgery Center LLC
bd_8af3e03d49b06830 · schema v1 · pii pii-v1
Full breach record for The Mount Kisco Surgery Center LLC →The Ambulatory Surgery Center of Westchester (ASCW) notified 21,073 individuals of a data breach where an employee's email account was compromised via phishing between Oct 23 and Nov 3, 2023. The incident exposed names and protected health information. ASCW engaged forensic investigators, enhanced email security, and offered 12 months of identity protection services.
Vermont clock✗ VT AG >45 bday34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_98faef4f7fe7242fIndiana State AGfiled 2024-06-26Verified
- bd_9a8fe933940dea3eNew Hampshire State AGfiled 2024-06-26Verified
- bd_d25e9f8730294417HHS OCRfiled 2024-06-25(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-26-ambulatory-surgery-center-westchester-mount-kisco-surgery-center-data-breach-notice
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2024
- Raw hash
- 6063997005e3d9219f727187bd0fac45ad4628455cbd4e4e84d8f78ae9ddd90b
Reporting entity
- Name
- The Mount Kisco Surgery Center LLCnorm: the mount kisco surgery center
Victim entity
- Name
- The Mount Kisco Surgery Center LLCnorm: the mount kisco surgery center
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- May 30, 2024
- Notification sent
- Jun 26, 2024
- Affected individuals
- 21,073
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(236 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.