HackingTargetedIDENTITY_BASICLowContained
Aspire Rural Health System
bd_b55b7c1a2e890840 · schema v1 · pii pii-v1
Full breach record for Aspire Rural Health System →Aspire Rural Health System notified Vermont AG of a breach occurring Nov 2024-Jan 2025 where an unauthorized party accessed the internal network. Full names were exposed. No specific count provided. Credit monitoring offered.
Vermont clock✗ VT AG >45 bday41 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by bianlian about this victim predates this filing by 226 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_564811f065d22d83Indiana State AGfiled 2025-08-20Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-20-aspire-rural-health-system-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 20, 2025
- Raw hash
- 2dd812331791e2dca618badc8749d991a2c8c24602160a902c40c957771a297f
Reporting entity
- Name
- Aspire Rural Health Systemnorm: aspire rural health system
- Domain
- aspirerhs.org
Victim entity
- Name
- Aspire Rural Health Systemnorm: aspire rural health system
- Domain
- aspirerhs.org
Incident
- Discovered
- Nov 4, 2024
- Materiality determined
- Aug 20, 2025
- Notification sent
- Aug 20, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(289 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.