CHSPSC, LLC - Updated
ent_fd9d7c339056913ebdc7d482
Disclosures
14
State AG · 7 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
11,173,555
as filed · State AG ID
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHSPSC, LLC - Updated
- Normalized
- chspsc llc updated— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- 🦞Maine State AGas victim2023-10-03
CHSPSC, LLC, a healthcare organization, reported a data breach affecting 88 Maine residents. The breach occurred on January 28, 2023, and was discovered on February 2, 2023. The compromised information included names and Social Security numbers. Affected individuals were notified on March 20, 2023, and offered 24 months of identity theft protection services through Experian.
- 💎Delaware State AGas reporting2023-09-22
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, exploiting a previously unknown vulnerability (zero-day). Personal information of patients from Community Health Systems affiliates was disclosed, including names, SSNs, DOBs, and medical/financial data. CHSPSC and Fortra engaged the FBI and CISA, took systems offline, patched the software, and offered 24 months of credit monitoring.
- 🥔Idaho State AGas reporting2023-09-21
Fortra, LLC, a cybersecurity services provider, experienced a data incident impacting 1,202,699 individuals, including 96 Idaho residents. CHSPSC, LLC, Fortra's client, filed this addendum with the Idaho Attorney General. The investigation was ongoing, but notification notices were mailed to all affected individuals.
- 🥔Idaho State AGas reporting2023-04-18
CHSPSC, LLC reported an addendum to a data incident involving its vendor, Fortra, LLC. Fortra's GoAnywhere file transfer platform was compromised via a previously unknown vulnerability (zero-day) between Jan 28-30, 2023. The incident exposed personal information of approximately 11.1 million individuals, including names, SSNs, DOBs, and medical/insurance data. CHSPSC notified the Idaho Attorney General, FBI, and CISA, and offered 24 months of credit monitoring via Experian.
- 🦫Oregon State AGas victim2023-04-17
CHSPSC, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-17. The breach occurred during 1/28/2023 - 1/30/2023. The breach was discovered on 1/30/2023. 1,173,555 individuals were affected. Notice was sent on 3/27/2023.
- 🐻California State AGas victim2023-04-17
CHSPSC, LLC notified California residents of a security incident involving its vendor, Fortra, LLC. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform between January 28 and January 30, 2023. The breach exposed personal information of patients, including names, addresses, Social Security numbers, and medical diagnoses. Fortra took systems offline on January 31, 2023. CHSPSC is offering 24 months of credit monitoring.
- 🦞Maine State AGas victim2023-04-17
CHSPSC, LLC, a healthcare organization, reported a security breach discovered on February 2, 2023. The incident occurred on January 28, 2023. Following the breach, the company offered affected individuals 24 months of identity restoration and credit monitoring services through Experian IdentityWorks. The total number of affected individuals and the specific types of data compromised were detailed in a separate notice not included in this document.
- 🥔Idaho State AGas reporting2023-03-08
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC. Fortra exploited a previously unknown vulnerability (zero-day) in its GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of patient and employee data, including names, addresses, SSNs, and medical information. CHSPSC notified the Idaho Attorney General on March 8, 2023, offered 24 months of credit monitoring, and confirmed the incident was contained.
- 🦬Montana State AGas victim2023-03-08
CHSPSC, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2023-03-08. The breach occurred from 1/28/2023 to 1/30/2023. 99 Montana residents were affected.
- 🦞Maine State AGas victim2023-03-08
Healthcare entity CHSPSC, LLC reported a data breach that occurred on January 28, 2023, and was discovered on February 2, 2023. The company notified affected individuals on March 20, 2023. The total number of affected individuals and the specific types of information compromised were not disclosed in the summary notice, which referenced a separate correspondence for details. CHSPSC offered 24 months of identity restoration and credit monitoring services through Experian to those impacted.
- 🐻California State AGas victim2023-03-07
CHSPSC, LLC disclosed a third-party security incident involving vendor Fortra, LLC. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of personal information for CHSPSC affiliates, including patients and employees. Affected data included names, addresses, medical billing/insurance info, diagnoses, medications, dates of birth, and Social Security numbers. Fortra contained the incident on January 31, 2023. CHSPSC notified law enforcement (FBI, CISA) and is offering 24 months of credit monitoring.
- 🦫Oregon State AGas victim2023-03-07
CHSPSC, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-03-07. The breach occurred during 1/28/2023 - 1/30/2023. The breach was discovered on 2/2/2023.
- 🌲Washington State AGas victim2023-03-07
CHSPSC, LLC, a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-02-02 and filed notice on 2023-03-07. 559 Washington residents were affected. 33 days elapsed between awareness and notification. 5 days to identify the breach. 0 days to contain the breach.
- 💎Delaware State AGas reporting2023-03-06
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, involving exploitation of a previously unknown vulnerability (zero-day). Data disclosed included names, addresses, SSNs, DOBs, and medical/insurance information. Fortra contained the breach by taking systems offline, deleting attacker accounts, and issuing a patch. CHSPSC provided 24 months of credit monitoring and identity restoration services to affected individuals across multiple states.