CHSPSC, LLC, a professional services provider to Community Health Systems affiliates, disclosed a third-party security incident involving its vendor, Fortra, LLC. The incident involved unauthorized access to Fortra's GoAnywhere file transfer platform via a previously unknown vulnerability (zero-day) between January 28 and 30, 2023. The breach exposed patient and employee PII, including names, addresses, SSNs, dates of birth, and medical/insurance information. Fortra contained the incident by taking systems offline on January 31, 2023. CHSPSC notified the Delaware Attorney General and offered 24 months of credit monitoring and identity restoration services to affected individuals.