CHSPSC, LLC
bd_fb0d0d6b9ca586f2 · schema v1 · pii pii-v1
Full breach record for CHSPSC, LLC →7 incidents on fileCHSPSC, LLC, a professional services provider to Community Health Systems affiliates, disclosed a third-party security incident involving its vendor, Fortra, LLC. The incident involved unauthorized access to Fortra's GoAnywhere file transfer platform via a previously unknown vulnerability (zero-day) between January 28 and 30, 2023. The breach exposed patient and employee PII, including names, addresses, SSNs, dates of birth, and medical/insurance information. Fortra contained the incident by taking systems offline on January 31, 2023. CHSPSC notified the Delaware Attorney General and offered 24 months of credit monitoring and identity restoration services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 28, 2023
Begins
Jan 30, 2023
Discovered
Mar 6, 2023
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_144a7bbc8ed5de672023-03-06Verified
- New Hampshire State AGbd_9d2239f17a10feb92023-03-10 · +4dVerified
- New Hampshire State AGbd_2bde52fe641f21a12023-04-21 · +46dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Mar 6 (IN), last Apr 21 (NH) — a 46-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.