HackingData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMINORMediumContained
Moses-Weitzman Health System, Inc.
bd_de0962eda247ff49 · schema v1 · pii pii-v1
Full breach record for Moses-Weitzman Health System, Inc. →Moses/Weitzman Health System, Inc. notified employees, dependents, and contractors of a data breach discovered on January 2, 2025. A sophisticated criminal actor accessed the IT environment and exfiltrated data including names, SSNs, DOBs, health insurance info, and government IDs. The incident is contained; forensic investigators were retained and identity theft protection services are offered.
Vermont clock⏱ VT AG >14 bday28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_06c323e4f068c974Maine State AGfiled 2025-01-30Candidate
- bd_5a05001fa8c1ba75New Hampshire State AGfiled 2025-01-30Verified
- bd_abcbf8032b31cc54Maryland State AGfiled 2025-01-30Verified
- bd_b72ef11708d0139aIndiana State AGfiled 2025-01-30Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-01-30-moses-weitzman-health-system-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 4fc822b5463624125874c982d4cde37e8cfdbbf23f6194dc858c38a265912a7b
Reporting entity
- Name
- Moses-Weitzman Health System, Inc.norm: moses weitzman health system
Victim entity
- Name
- Moses-Weitzman Health System, Inc.norm: moses weitzman health system
Incident
- Discovered
- Jan 2, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.