Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICLowContained
Onsite Mammography
bd_a946536717595088 · schema v1 · pii pii-v1
Full breach record for Onsite Mammography →Onsite Mammography, LLC notified consumers of a data security incident discovered in October 2024 involving unauthorized access to an employee's email account. The incident exposed patients' names and specific health-related information (PHI). The company engaged independent cybersecurity experts and a data analytics vendor to investigate and assess the scope.
Vermont clock✗ VT AG >45 bday29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_a96b83cee14ef51fHHS OCRfiled 2025-04-21Verified
- bd_b49795f765e873bcIndiana State AGfiled 2025-04-21Verified
- bd_c686ace3fe4924d6New Hampshire State AGfiled 2025-04-21Verified
- bd_c85f887b9fa8986bMaine State AGfiled 2025-04-21Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-21-onsite-mammography-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2025
- Raw hash
- 28b79b3a750e3685706dccb47f53134196a7d02aaac018289803170589f513e9
Reporting entity
- Name
- Onsite Mammographynorm: onsite mammography
Victim entity
- Name
- Onsite Mammographynorm: onsite mammography
Incident
- Discovered
- Oct 1, 2024
- Materiality determined
- —
- Notification sent
- Apr 21, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 29 weeks(202 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.