HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICAUTHENTICATIONBIOMETRICMediumContained
NorthBay Healthcare Corporation
bd_9e74ae9ee1e29801 · schema v1 · pii pii-v1
Full breach record for NorthBay Healthcare Corporation →Northbay Healthcare Corporation notified consumers of a data breach where an unauthorized third party accessed files between Jan 11 and Apr 1, 2024. Compromised data included names, SSNs, medical info, and financial details. The company engaged forensic investigators and law enforcement, enhanced security measures, and offered credit monitoring.
Vermont clock✗ VT AG >45 bday49 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3e24cc6d7f940850Oregon State AGfiled 2025-01-29Candidate
- bd_48556d100c6d2adcMaine State AGfiled 2025-01-29Verified
- bd_84b37cb0f778512bCalifornia State AGfiled 2025-01-29Verified by operator
- bd_e0f4c14e6c397f7bMontana State AGfiled 2025-01-29Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-01-29-northbay-healthcare-corporation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2025
- Raw hash
- 4cdfab228e213d88b9f13adab2e5487409b7339180888a8076ca0a2bfb5a0473
Reporting entity
- Name
- NorthBay Healthcare Corporationnorm: northbay healthcare
Victim entity
- Name
- NorthBay Healthcare Corporationnorm: northbay healthcare
Incident
- Discovered
- Feb 23, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICAUTHENTICATIONBIOMETRIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- coordinated with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 49 weeks(341 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.