DisclosureLens
HackingHealthcareHealthcareStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)MediumContained

Aya Healthcare

bd_a9f3734972f43502 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 12, 2025

Filed

Feb 27, 2025

To disclose

7 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

67%
Full breach record for Aya Healthcare

Aya Healthcare, Inc. notified consumers that unauthorized third parties used credentials obtained from unrelated sources to access user accounts via automated bots on January 12 and 19, 2025. Affected data included names, contact info, SSNs, nursing license numbers, and vaccination status. Aya reset passwords and offered 24 months of credit monitoring.

Vermont clock VT AG >14 bday7 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 7 weeks / 46 days

Jan 12, 2025

Discovered

Feb 27, 2025

Filed

vs. sector median

5 wks faster

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filings

Filing propagation · 7 filings · 7 states

View merged incident ↗
Indiana State AGFeb 27 · first
Montana State AGFeb 27 · first
Maryland State AGFeb 27 · first
Massachusetts State AGFeb 27 · first
Maine State AGFeb 27 · first
Nebraska State AGFeb 27 · first
Vermont State AGFeb 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.