AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_BASICPIILowContained
The Open
bd_dcd5395163f6c58f · schema v1 · pii pii-v1
Full breach record for The Open →Open Practice Solutions notified Vermont consumers of a data error on June 26, 2025. A software update misconfiguration in its billing portal allowed another customer to access billing information (name, provider, service details) for approximately five hours. No SSN, financial, or health insurance data was exposed. No evidence of misuse was found.
Vermont clock✗ VT AG >45 bday15 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-10-open-practice-solutions-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 10, 2025
- Raw hash
- 668a8e7611bb7a791d7e868e69693024dd63e459cd95c26fb025a55fd25f18ce
Reporting entity
- Name
- The Opennorm: the open
- Domain
- theopen.com
Victim entity
- Name
- The Opennorm: the open
- Domain
- theopen.com
Incident
- Discovered
- Jun 26, 2025
- Materiality determined
- —
- Notification sent
- Oct 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.