The Vermont Office of the Attorney General disclosed a data breach affecting Intellihartx, LLC, linked to a vulnerability in its third-party secure file transfer protocol provider, Fortra, discovered on February 2, 2023. The incident exposed sensitive personal and medical data of 988 Rhode Island residents, including names, addresses, medical billing/insurance details, diagnoses, medications, dates of birth, and Social Security numbers. The breach was formally reported on June 8, 2023, indicating a delayed public notification. The compromised data particularly Social Security numbers and medical records poses significant risks of identity theft, financial fraud, and unauthorized access to private health information. Given the nature of the exposed data, the breach falls under a high-severity category due to the potential for long-term harm to affected individuals, including reputational damage to Intellihartx and possible regulatory penalties for failing to safeguard protected health information (PHI) under laws like HIPAA.
Source: https://ago.vermont.gov/document/2023-06-08-intellihartx-data-breach-notice-consumers
TPRM report: https://www.rankiteo.com/company/itx-companies
"id": "itx1023090725",
"linkid": "itx-companies",
"type": "Breach",
"date": "2/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '988 (Rhode Island residents)',
'industry': 'Healthcare',
'location': 'USA (affecting Rhode Island residents)',
'name': 'Intellihartx, LLC',
'type': 'Healthcare Provider / Organization'},
{'industry': 'Cybersecurity / File Transfer Services',
'name': 'Fortra (Secure File Transfer Protocol '
'Provider)',
'type': 'Third-Party Vendor'}],
'data_breach': {'data_exfiltration': 'Likely (data exposed via compromised '
'file transfer protocol)',
'number_of_records_exposed': '988',
'personally_identifiable_information': ['Names',
'Addresses',
'Date of birth',
'Social Security '
'numbers',
'Medical billing and '
'insurance '
'information',
'Diagnoses',
'Medications'],
'sensitivity_of_data': 'High (includes SSN, medical records, '
'and financial data)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)']},
'date_detected': '2023-02-02',
'date_publicly_disclosed': '2023-06-08',
'description': 'The Vermont Office of the Attorney General reported that '
'Intellihartx, LLC experienced a data breach involving its '
'secure file transfer protocol provider, Fortra, on February '
'2, 2023. Approximately 988 Rhode Island residents were '
'affected, with potential exposure of names, addresses, '
'medical billing and insurance information, diagnoses, '
'medications, date of birth, and Social Security numbers.',
'impact': {'data_compromised': ['Names',
'Addresses',
'Medical billing and insurance information',
'Diagnoses',
'Medications',
'Date of birth',
'Social Security numbers'],
'identity_theft_risk': 'High (PII and medical data exposed)',
'systems_affected': ['Secure File Transfer Protocol (Fortra)']},
'references': [{'date_accessed': '2023-06-08',
'source': 'Vermont Office of the Attorney General'}],
'regulatory_compliance': {'regulations_violated': ['HIPAA (likely, due to PHI '
'exposure)',
'State data breach '
'notification laws (e.g., '
'Rhode Island, Vermont)'],
'regulatory_notifications': ['Vermont Office of the '
'Attorney General',
'Potentially HHS (for '
'HIPAA violations)']},
'response': {'communication_strategy': 'Public disclosure via Vermont Office '
'of the Attorney General'},
'title': "Intellihartx, LLC Data Breach via Fortra's Secure File Transfer "
'Protocol',
'type': 'Data Breach'}