Confirmed breach. Intrusion Jan 28, 2023–Jan 30, 2023, discovered Jan 30, 2023 — the first regulatory filing landed 234 days later. 1,202,699 individuals reported across the linked filings.
Fortra, LLC, a cybersecurity services provider, experienced a data incident impacting 1,202,699 individuals, including 96 Idaho residents. CHSPSC, LLC, Fortra's client, filed this addendum with the Idaho Attorney General. The investigation was ongoing, but notification notices were mailed to all affected individuals.
Affected (this filing): 1,202,699
💎Delaware State AGMost recentlinked via multistate filing link · 100%
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, exploiting a previously unknown vulnerability (zero-day). Personal information of patients from Community Health Systems affiliates was disclosed, including names, SSNs, DOBs, and medical/financial data. CHSPSC and Fortra engaged the FBI and CISA, took systems offline, patched the software, and offered 24 months of credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.