HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICCriticalContained
Singing River Health System and its wholly owned subsidiary, Singing River Gulfport
bd_be089a5fc3dc79bd · schema v1 · pii pii-v1
Full breach record for Singing River Health System and its wholly owned subsidiary, Singing River Gulfport →Singing River Health System (Mississippi) reported an external system breach (hacking) occurring on 08/19/2023, discovered on 12/18/2023. The incident affected 895,204 individuals, including 25 Maine residents. Acquired data included names and Social Security Numbers. The entity notified affected individuals on 05/13/2024 and offered identity theft protection services.
Maine clockDiscovered Dec 18, 2023 → Filed with AG May 13, 2024147d ✗ ME AG >90d21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed895,204 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/cbc854c8-d142-4f56-b114-91952ab24d34.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2024
- Raw hash
- 3b96b242b4dff75e62b9ecdb064c57d7ba061e43b39400783a0e634d98d2288c
Reporting entity
- Name
- Singing River Health System and its wholly owned subsidiary, Singing River Gulfportnorm: singing river health system and its wholly owned subsidiary singing river gulfport
Victim entity
- Name
- Singing River Health System and its wholly owned subsidiary, Singing River Gulfportnorm: singing river health system and its wholly owned subsidiary singing river gulfport
Incident
- Discovered
- Dec 18, 2023
- Materiality determined
- May 13, 2024
- Notification sent
- May 13, 2024
- Affected individuals
- 895,204
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(147 days from discovery to filing)
- Compliance flags
- ME AG >90d · 147dME resident >60d · 147d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 18, 2023→ Filed with AG: May 13, 2024147d 90 days ME AG >90d Maine Discovered: Dec 18, 2023→ Notified: May 13, 2024147d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.