The Vitality Group
ent_a6f7c8d8c5f73c02cc7bfa4f
Disclosures
14
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
20,387
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Vitality Group
- Normalized
- the vitality— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- New Hampshire State AGas victim2023-07-18
Vitality Group, LLC, a third-party vendor for Alert Holding Company, Inc., experienced a security incident involving the MOVEit file transfer software. The incident exploited a zero-day vulnerability discovered on May 30, 2023. Vitality detected the risk on June 1, 2023, and isolated the server. The breach affected 7 New Hampshire residents, exposing personal information including SSNs. Vitality patched the vulnerability, reset passwords, and offered credit monitoring.
- Maine State AGas victim2023-07-17
The Vitality Group, LLC reported a data breach affecting one Maine resident, which was discovered on June 1, 2023. The breach occurred on May 30, 2023, due to a compromise of Progress Software Corporation's MOVEit, a third-party software. The compromised information includes names and Social Security numbers. The company provided written notification to the affected individual on July 17, 2023, and offered 24 months of credit monitoring and identity theft protection services through Experian.
- Maine State AGas victim2023-07-17
The Vitality Group, LLC reported a third-party software breach involving Progress Software's MOVEit on May 30, 2023. The incident compromised names and Social Security Numbers of 2,071 individuals, including 1 Maine resident. Notification was sent on July 7, 2023, with 24 months of credit monitoring offered.
- Montana State AGas victim2023-07-17
The Vitality Group, LLC notified affected individuals of a data security incident involving the MOVEit file transfer program. The vulnerability allowed unauthorized access to a server on May 30, 2023. Exposed data included names, Social Security numbers, dates of birth, and wellness activity participation indicators. Vitality disconnected the server on June 1, 2023, and offered two years of credit monitoring via Experian.
- New Hampshire State AGas victim2023-07-14
The Vitality Group, LLC reported a security incident involving the MOVEit file transfer vulnerability. The zero-day vulnerability was identified on May 30, 2023, and detected by Vitality on June 1, 2023. An unauthorized third party accessed the server for a two-hour span. 9 New Hampshire residents were affected, with personal information including names and Social Security numbers potentially exposed. Vitality disconnected the server, applied patches, reset passwords, and offered credit monitoring via Experian.
- Maine State AGas victim2023-07-13
The Vitality Group, LLC reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on May 30, 2023. The breach was discovered on June 1, 2023, and affected 7 Maine residents. The compromised information included names or other personal identifiers in combination with Social Security Numbers. Affected individuals were notified on July 17, 2023, and offered 24 months of credit monitoring and identity theft protection services from Experian.
- Maine State AGas reporting2023-07-12
The Vitality Group, LLC, filed a data breach notice with the Maine Attorney General regarding an incident involving bioMérieux. The breach, occurring on May 30, 2023, and discovered on June 1, 2023, involved the compromise of third-party software (MOVEit). Approximately 10,244 individuals were affected, including 2 Maine residents. The breach exposed names and Social Security Numbers. The entity provided 24 months of credit monitoring and identity theft insurance through Experian.
- ILLINOISHHS OCRas victim2023-07-11
The Vitality Group, LLC (a Business Associate, IL) reported to HHS OCR on 2023-07-11 a Hacking/IT Incident affecting 20,387 individuals. A software application exposed PHI stored on a Network Server, including names, dates of birth, addresses, and Social Security numbers. The BA notified HHS and affected individuals, offered complimentary credit monitoring, and implemented additional administrative, technical, and security safeguards.
- Montana State AGas victim2023-07-06
Supplemental notice from Montana AG regarding a breach at The Vitality Group, LLC (vendor to bioMérieux). Vitality discovered exploitation of MOVEit Transfer on June 1, 2023. Compromised data includes SSNs, DOBs, and health information. Initial notice sent June 15, 2023. Credit monitoring offered.
- Maine State AGas victim2023-06-30
The Vitality Group, LLC reported a cybersecurity incident involving the MOVEit software vulnerability (Progress Software Corporation). The breach occurred on May 30, 2023, and was discovered on June 1, 2023. Approximately 4,392 individuals were affected, including 8 Maine residents. The incident involved the compromise of names and Social Security Numbers. The company provided written notification and offered 24 months of credit monitoring and identity theft protection services through Experian.
- Massachusetts State AGas victim2023-06-30
The Vitality Group, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-30. 293 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2023-01-01
THE VITALITY GROUP, LLC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-471). The register records the breach as discovered on May 30, 2023. Additional entities named: CARESOURCE MANAGEMENT, LLC, MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
THE VITALITY GROUP, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-442). The register records the breach as discovered on May 30, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
THE VITALITY GROUP filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-436). The register records the breach as discovered on June 1, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- The Vitality Group’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).