HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedTargetedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Catholic Charities of the Diocese of Rockville Centre
bd_9692e7d8d8bad845 · schema v1 · pii pii-v1
Full breach record for Catholic Charities of the Diocese of Rockville Centre →Catholic Charities of Long Island experienced a data breach in September 2023 affecting approximately 13,000 patients. The incident was detected on September 3, 2023, when unusual network activity was observed. The organization disconnected network access and engaged a third-party cybersecurity firm. The breach involved unauthorized access to patient records containing PII and PHI.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a4ce6d5557f1ecb2Maine State AGfiled 2023-11-16(11d gap)Verified
- bd_f7700ca58694302bMontana State AGfiled 2023-11-15(12d gap)Candidate
- bd_0da38bc84853e9cfVermont State AGfiled 2023-11-14(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/catholic-charities-diocese-rockville-centre-dba-catholic-charities-long-island-20231127.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 27, 2023
- Raw hash
- 9db28a75b657af6f21c47e1b03caf739a1a517fab903f9d3e36cf5ae45edf9c8
Reporting entity
- Name
- Catholic Charities of the Diocese of Rockville Centrenorm: catholic charities of the diocese of rockville centre
Victim entity
- Name
- Catholic Charities of the Diocese of Rockville Centrenorm: catholic charities of the diocese of rockville centre
Incident
- Discovered
- Sep 3, 2023
- Materiality determined
- —
- Notification sent
- Nov 2, 2023
- Affected individuals
- 13,000
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1595 Active ScanningT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.