CHSPSC, LLC
ent_9f4eb92d9ea9e2d06b0ae1f8
Disclosures
23
State AG · HHS OCR enforcement · 13 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
1,202,699
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHSPSC, LLC
- Normalized
- chspsc— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (23)newest first
- Maine State AGas victim2023-10-03
CHSPSC, LLC, a healthcare organization, reported a data breach affecting 88 Maine residents. The breach occurred on January 28, 2023, and was discovered on February 2, 2023. The compromised information included names and Social Security numbers. Affected individuals were notified on March 20, 2023, and offered 24 months of identity theft protection services through Experian.
- Delaware State AGas reporting2023-09-22
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, exploiting a previously unknown vulnerability (zero-day). Personal information of patients from Community Health Systems affiliates was disclosed, including names, SSNs, DOBs, and medical/financial data. CHSPSC and Fortra engaged the FBI and CISA, took systems offline, patched the software, and offered 24 months of credit monitoring.
- Idaho State AGas reporting2023-09-21
Fortra, LLC, a cybersecurity services provider, experienced a data incident impacting 1,202,699 individuals, including 96 Idaho residents. CHSPSC, LLC, Fortra's client, filed this addendum with the Idaho Attorney General. The investigation was ongoing, but notification notices were mailed to all affected individuals.
- Massachusetts State AGas victim2023-05-11
CHSPSC, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-11. 276 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-04-21
CHSPSC, LLC filed a supplemental notice regarding the Fortra GoAnywhere file transfer service breach. The incident occurred Jan 28-30, 2023, exploiting a previously unknown vulnerability. CHSPSC discovered the impact on Feb 2, 2023. 1,173,555 individuals affected, including 109 NH residents. Data types include PII and government IDs. Remediation included patching, rebuilding platform, and offering credit monitoring.
- Idaho State AGas reporting2023-04-18
CHSPSC, LLC reported an addendum to a data incident involving its vendor, Fortra, LLC. Fortra's GoAnywhere file transfer platform was compromised via a previously unknown vulnerability (zero-day) between Jan 28-30, 2023. The incident exposed personal information of approximately 11.1 million individuals, including names, SSNs, DOBs, and medical/insurance data. CHSPSC notified the Idaho Attorney General, FBI, and CISA, and offered 24 months of credit monitoring via Experian.
- Oregon State AGas victim2023-04-17
CHSPSC, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-17. The breach occurred during 1/28/2023 - 1/30/2023. The breach was discovered on 1/30/2023. 1,173,555 individuals were affected. Notice was sent on 3/27/2023.
- California State AGas victim2023-04-17
CHSPSC, LLC notified California residents of a security incident involving its vendor, Fortra, LLC. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform between January 28 and January 30, 2023. The breach exposed personal information of patients, including names, addresses, Social Security numbers, and medical diagnoses. Fortra took systems offline on January 31, 2023. CHSPSC is offering 24 months of credit monitoring.
- Maine State AGas victim2023-04-17
CHSPSC, LLC, a healthcare organization, reported a security breach discovered on February 2, 2023. The incident occurred on January 28, 2023. Following the breach, the company offered affected individuals 24 months of identity restoration and credit monitoring services through Experian IdentityWorks. The total number of affected individuals and the specific types of data compromised were detailed in a separate notice not included in this document.
- South Carolina State AGas victim2023-03-13
CHSPSC, LLC notified South Carolina residents of a third-party security incident involving vendor Fortra, LLC. Fortra's GoAnywhere file transfer platform was compromised via a previously unknown vulnerability (zero-day) between Jan 28-30, 2023. Disclosed data included names, addresses, SSNs, DOBs, and medical/billing info for patients, employees, and others. CHSPSC engaged the FBI and CISA, patched systems, and offered 24 months of credit monitoring.
- New Hampshire State AGas victim2023-03-10
CHSPSC, LLC notified the NH Attorney General of a third-party data incident involving its vendor Fortra, LLC. Fortra exploited a previously unknown vulnerability in its GoAnywhere file transfer platform between Jan 28-30, 2023. CHSPSC was notified on Feb 2, 2023. Affected data includes names, addresses, SSNs, DOBs, medical diagnoses, and medical billing info. The incident is contained. CHSPSC is offering 24 months of credit monitoring.
- Idaho State AGas reporting2023-03-08
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC. Fortra exploited a previously unknown vulnerability (zero-day) in its GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of patient and employee data, including names, addresses, SSNs, and medical information. CHSPSC notified the Idaho Attorney General on March 8, 2023, offered 24 months of credit monitoring, and confirmed the incident was contained.
- Montana State AGas victim2023-03-08
CHSPSC, LLC notified Montana consumers of a third-party security incident involving vendor Fortra, LLC. Unauthorized access occurred Jan 28-30, 2023, via exploitation of a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform. CHSPSC was notified Feb 2, 2023. Disclosed data included names, addresses, SSNs, DOBs, and medical/billing information. Incident is contained; credit monitoring offered.
- Maine State AGas victim2023-03-08
Healthcare entity CHSPSC, LLC reported a data breach that occurred on January 28, 2023, and was discovered on February 2, 2023. The company notified affected individuals on March 20, 2023. The total number of affected individuals and the specific types of information compromised were not disclosed in the summary notice, which referenced a separate correspondence for details. CHSPSC offered 24 months of identity restoration and credit monitoring services through Experian to those impacted.
- California State AGas victim2023-03-07
CHSPSC, LLC disclosed a third-party security incident involving vendor Fortra, LLC. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of personal information for CHSPSC affiliates, including patients and employees. Affected data included names, addresses, medical billing/insurance info, diagnoses, medications, dates of birth, and Social Security numbers. Fortra contained the incident on January 31, 2023. CHSPSC notified law enforcement (FBI, CISA) and is offering 24 months of credit monitoring.
- Oregon State AGas victim2023-03-07
CHSPSC, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-03-07. The breach occurred during 1/28/2023 - 1/30/2023. The breach was discovered on 2/2/2023.
- Washington State AGas victim2023-03-07
CHSPSC, LLC reported a third-party security incident involving vendor Fortra, LLC. Unauthorized access occurred Jan 28-30, 2023, via exploitation of a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform. CHSPSC was notified on Feb 2, 2023. Affected data included names, addresses, SSNs, DOBs, and medical/billing information for 559 Washington residents. Incident is contained; credit monitoring offered.
- Indiana State AGas victim2023-03-06
CHSPSC LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2023-01-28 and was reported on 2023-03-06. 148,931 Indiana residents were affected. 1,202,699 individuals affected in total.
- Delaware State AGas reporting2023-03-06
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, involving exploitation of a previously unknown vulnerability (zero-day). Data disclosed included names, addresses, SSNs, DOBs, and medical/insurance information. Fortra contained the breach by taking systems offline, deleting attacker accounts, and issuing a patch. CHSPSC provided 24 months of credit monitoring and identity restoration services to affected individuals across multiple states.
- Delaware State AGas victim2023-03-06
CHSPSC, LLC, a professional services provider to Community Health Systems affiliates, disclosed a third-party security incident involving its vendor, Fortra, LLC. The incident involved unauthorized access to Fortra's GoAnywhere file transfer platform via a previously unknown vulnerability (zero-day) between January 28 and 30, 2023. The breach exposed patient and employee PII, including names, addresses, SSNs, dates of birth, and medical/insurance information. Fortra contained the incident by taking systems offline on January 31, 2023. CHSPSC notified the Delaware Attorney General and offered 24 months of credit monitoring and identity restoration services to affected individuals.
- Illinois State AGas victim2023-01-01
CHSPSC, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-654). The register records the breach as discovered on March 8, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
CHSPSC, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-261). The register records the breach as discovered on January 28, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALHHS OCR enforcementas victim2020-09-23
CHSPSC LLC, a HIPAA business associate providing IT and health information management services to Community Health Systems hospitals, agreed to pay $2.3 million to settle potential HIPAA Privacy and Security Rules violations related to a breach affecting over six million individuals.
Supply-chain cascadesreviewed and confirmed
- CHSPSC, LLC’s filing is one of at least 12 in the FORTRA, LLC supply-chain incident (2023).