HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Bone & Joint Clinic, S.C.
bd_abfe4c8408c67439 · schema v1 · pii pii-v1
Full breach record for Bone & Joint Clinic, S.C. →Bone & Joint Clinic, S.C. reported a data security incident on January 16, 2023, involving unauthorized access to administrative and medical files. Affected data included names, DOBs, SSNs, addresses, phone numbers, health insurance info, and diagnosis/treatment details. The clinic engaged cybersecurity experts, notified the FBI, enhanced network security, and offered credit monitoring services.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_786ca69621261d8bHHS OCRfiled 2023-03-13(6d gap)Candidate
- bd_8d202bdbb06effceMontana State AGfiled 2023-03-14(7d gap)Candidate
- bd_49594d62d05a0739New Hampshire State AGfiled 2023-03-20(13d gap)Verified
- bd_7531a824bea14cf7Maine State AGfiled 2023-03-20(13d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-03-07-bone-joint-clinic-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 7, 2023
- Raw hash
- fc577e1f3797b3e835e153da4a8eee17f9c51ff0382534823a1c856b0d6552c4
Reporting entity
- Name
- Bone & Joint Clinic, S.C.norm: bone joint clinic sc
Victim entity
- Name
- Bone & Joint Clinic, S.C.norm: bone joint clinic sc
Incident
- Discovered
- Jan 16, 2023
- Materiality determined
- Mar 7, 2023
- Notification sent
- Mar 7, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.