HackingData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
The Chattanooga Heart Institute
bd_aa1ec43b034d9698 · schema v1 · pii pii-v1
Full breach record for The Chattanooga Heart Institute →The Chattanooga Heart Institute experienced a cybersecurity attack between March 8-16, 2023, identified on April 17, 2023. Unauthorized access led to the exfiltration of patient PHI, including names, SSNs, DOBs, driver's licenses, and health insurance info. The Institute engaged forensic vendors, notified federal law enforcement, and provided one year of Equifax identity monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday49 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by karakurt about this victim predates this filing by 309 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5659cfb7865d2e45New Hampshire State AGfiled 2024-03-28(1d gap)Verified
- bd_a2267e549573aa93Maine State AGfiled 2024-03-28(1d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-27-chattanooga-heart-institute-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2024
- Raw hash
- ecf50dd7a1ff50bc30802673e24244b760a02bc1c4b246f739c693ee46913a53
Reporting entity
- Name
- The Chattanooga Heart Institutenorm: the chattanooga heart institute
Victim entity
- Name
- The Chattanooga Heart Institutenorm: the chattanooga heart institute
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Oct 6, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 49 weeks(345 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.