HackingStolen CredentialsTargetedIDENTITY_BASICLowContained
Southwest Healthcare Services
bd_c057300c877b220e · schema v1 · pii pii-v1
Full breach record for Southwest Healthcare Services →Southwest Healthcare Services notified Vermont AG that an unauthorized actor accessed its network between Oct 28-29, 2022. The breach, discovered Jan 31, 2023, exposed names. The company secured the network and engaged outside cybersecurity professionals for investigation. No evidence of identity theft was found. Consumers were advised to place fraud alerts or security freezes on credit files.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by donutleaks about this victim predates this filing by 160 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d333197f85b58141Leak Sitedonutleaksfiled 2022-10-22(160d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_0c8778d9b0a5454dWashington State AGfiled 2023-03-31Verified by operator
- bd_3e7012f6243e4f0dMontana State AGfiled 2023-03-31Verified by operator
- bd_77a08581489e18adVermont State AGfiled 2023-03-31Verified by operator
- bd_b9a3d1a0f4aeea7dHHS OCRfiled 2023-04-01(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-03-31-southwest-healthcare-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2023
- Raw hash
- b7e8e1375796bd8bbfd0bede728bd8b8a4595438a4e70bb21f324267d6a29f05
Reporting entity
- Name
- Southwest Healthcare Servicesnorm: southwest healthcare
Victim entity
- Name
- Southwest Healthcare Servicesnorm: southwest healthcare
Incident
- Discovered
- Jan 31, 2023
- Materiality determined
- —
- Notification sent
- Mar 31, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.