HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
VITAS Hospice Services, LLC
bd_957dc05d7fd8cd4f · schema v1 · pii pii-v1
Full breach record for VITAS Hospice Services, LLC →VITAS Hospice Services, LLC disclosed a data breach where an unauthorized party compromised a vendor account to access VITAS systems between September 21 and October 27, 2025. The incident was discovered on October 24, 2025. Personal information, including PHI and PII, of patients and former patients was accessed and downloaded. VITAS engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_543c7050b8043fb5Texas State AGfiled 2025-11-21(2d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614472
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 19, 2025
- Raw hash
- 52c02714236534846158601d17ece04b467fbf0268251c14f43c050a482bc48d
Reporting entity
- Name
- VITAS Hospice Services, LLCnorm: vitas hospice
Victim entity
- Name
- VITAS Hospice Services, LLCnorm: vitas hospice
Incident
- Discovered
- Oct 24, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.