HackingSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Rightway
bd_ec805992153363bf · schema v1 · pii pii-v1
Full breach record for Rightway →Davis Polk & Wardwell LLP notified consumers of a data breach involving its third-party vendor, Rightway Healthcare. Unauthorized access occurred on September 23, 2023, affecting personal information including names, SSNs, and DOBs of Davis Polk personnel and eligible dependents. Rightway is a healthcare benefits provider. Davis Polk engaged the vendor, made regulatory notifications, and offered 24 months of credit monitoring via Experian. The incident status is contained.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2013-11-13-davis-polk-wardwell-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2013
- Raw hash
- a0611f858f3f43ddd26e59ad84326ff040fa78784de7ea4bfa71cefee32ed04e
Reporting entity
- Name
- DAVIS POLK & WARDWELL LLPnorm: davis polk wardwell
Victim entity
- Name
- Rightwaynorm: rightway
- Domain
- rightwayhealthcare.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 13, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Made regulatory notifications to the extent required
- Initial access
- trusted_relationship
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.