HackingData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Chattanooga Heart Institute
bd_98840e756fa81061 · schema v1 · pii pii-v1
Full breach record for The Chattanooga Heart Institute →The Chattanooga Heart Institute notified patients of a cybersecurity attack where an unauthorized third party accessed the network between March 8-16, 2023. The institute detected the incident on April 17, 2023, engaged forensic vendors, notified federal law enforcement, and provided free Equifax identity monitoring to affected individuals.
Leak gap clock⏱ Leak >30d15 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
A leak claim by karakurt about this victim predates this filing by 66 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e6c3c8f394d4bc2aLeak Sitekarakurtfiled 2023-05-23(66d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_27ff2e2d4479e8dbMontana State AGfiled 2023-07-28Verified by operator
- bd_371787f6f5dc7cf6Maine State AGfiled 2023-07-28Verified
- bd_e44f43fd3f7ecb1eHHS OCRfiled 2023-07-28Verified
- bd_4bc290ca5363ed84Maine State AGfiled 2024-02-13(200d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/chattanooga-heart-institute-20230728.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- 0f92b5c362886ef055bd62ce0051d77ded2af08cad99ae20606f57099e5012ce
Reporting entity
- Name
- The Chattanooga Heart Institutenorm: the chattanooga heart institute
Victim entity
- Name
- The Chattanooga Heart Institutenorm: the chattanooga heart institute
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.