HackingStolen CredentialsData ExfiltratedIDENTITY_BASICPHIHEALTH_BASICLowContained
Bayhealth Medical Center
bd_a959cc94549ef956 · schema v1 · pii pii-v1
Full breach record for Bayhealth Medical Center →Bayhealth Medical Center notified consumers of a cybersecurity incident where unauthorized access occurred between July 27 and July 31, 2024. The breach impacted names and Protected Health Information (PHI). The organization engaged forensic specialists, notified federal law enforcement, and is offering 12-24 months of credit monitoring. The incident status is contained.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_362157ac2cddd018Montana State AGfiled 2025-02-03Verified
- bd_470d92e7afe21bdeMaine State AGfiled 2025-02-03Candidate
- bd_6d0e5c321460c8b6Delaware State AGfiled 2025-02-03Verified
- bd_79aca51b0000ac77New Hampshire State AGfiled 2025-02-03Verified
Show 2 more filings ↓Show fewer ↑
- bd_950fc14168978470California State AGfiled 2025-02-03Verified
- bd_e01aeff7b3ae70e7Delaware State AGfiled 2025-02-03Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-03-bayhealth-medical-center-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 3, 2025
- Raw hash
- e2cfb882db30704215cce680a576241f7501e4d6b93be84c2f3aa72b0b59580c
Reporting entity
- Name
- Bayhealth Hospitalnorm: bayhealth hospital
- Domain
- bayhealth.org
Victim entity
- Name
- Bayhealth Medical Centernorm: bayhealth medical center
Incident
- Discovered
- Jul 31, 2024
- Materiality determined
- Feb 3, 2025
- Notification sent
- Feb 3, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- notified federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(187 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.