HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
CHSPSC, LLC - Updated
bd_bf411ffed68cd2ce · schema v1 · pii pii-v1
Full breach record for CHSPSC, LLC - Updated →CHSPSC, LLC notified California residents of a security incident involving its vendor, Fortra, LLC. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform between January 28 and January 30, 2023. The breach exposed personal information of patients, including names, addresses, Social Security numbers, and medical diagnoses. Fortra took systems offline on January 31, 2023. CHSPSC is offering 24 months of credit monitoring.
California clockDiscovered Jan 30, 2023 → Notified Mar 24, 202352d ✓ CA 60-day OK11 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_05ff925166a4537fOregon State AGfiled 2023-04-17Verified
- bd_fefafc85063dc9bbMaine State AGfiled 2023-04-17Verified
- bd_8d82685405a418fcMontana State AGfiled 2023-03-08(40d gap)Verified
- bd_e8298cc5c3b2011eMaine State AGfiled 2023-03-08(40d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 41d gap
- bd_0d9ab92e55f3d8a0California State AGfiled 2023-03-07(41d gap)Candidate
- bd_2b73da2633a307ffOregon State AGfiled 2023-03-07(41d gap)Verified
- bd_ee40a8445255d063Washington State AGfiled 2023-03-07(41d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565652
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2023
- Raw hash
- 1b3013b415d691aacbd5328025a2b54aa9b22f493c163a97bb3efc5d093a1c19
Reporting entity
- Name
- CHSPSC, LLC - Updatednorm: chspsc llc updated
Victim entity
- Name
- CHSPSC, LLC - Updatednorm: chspsc llc updated
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- —
- Notification sent
- Mar 24, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified FBINotified CISA
- Third party
- via Fortra, LLC
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 52d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 30, 2023→ Notified: Mar 24, 202352d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.