The Vermont Attorney General's Office disclosed a **data breach** affecting **Next Step Healthcare, LLC**, which was detected on **June 5, 2024**, but reported publicly on **May 29, 2025**. The incident involved the unauthorized exposure of **personal information**, including **names and unspecified data elements** of individuals associated with the company. The exact number of affected individuals remains **undetermined**, raising concerns about the scope of the breach. While the specific attack vector (e.g., phishing, system vulnerability) was not detailed, the compromise of **personal data**—even without explicit confirmation of financial or highly sensitive records—suggests a **significant privacy risk** for patients, employees, or clients. The delay in public disclosure further complicates trust and potential mitigation efforts. No evidence of ransomware or large-scale operational disruption was reported, but the breach underscores vulnerabilities in healthcare data protection.
Source: https://ago.vermont.gov/document/2025-05-29-next-step-healthcare-data-breach-notice-consumers
TPRM report: https://www.rankiteo.com/company/nextstephc
"id": "nex1007091725",
"linkid": "nextstephc",
"type": "Breach",
"date": "6/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unknown',
'industry': 'Healthcare',
'location': 'Vermont, USA (assumed based on reporting '
'entity)',
'name': 'Next Step Healthcare, LLC',
'type': 'Healthcare Provider'}],
'data_breach': {'number_of_records_exposed': 'Unknown',
'personally_identifiable_information': True,
'sensitivity_of_data': 'Moderate to High (includes names and '
'unspecified elements)',
'type_of_data_compromised': ['Personal Information']},
'date_detected': '2024-06-05',
'date_publicly_disclosed': '2025-05-29',
'description': "The Vermont Attorney General's Office reported a data breach "
'involving Next Step Healthcare, LLC. The breach potentially '
'affected personal information, including names and other '
'unspecified data elements. The number of individuals affected '
'is currently unknown.',
'impact': {'data_compromised': ['names', 'unspecified data elements'],
'identity_theft_risk': 'Potential (personal information exposed)'},
'investigation_status': 'Ongoing (number of affected individuals unknown)',
'references': [{'date_accessed': '2025-05-29',
'source': "Vermont Attorney General's Office"}],
'regulatory_compliance': {'regulatory_notifications': 'Vermont Attorney '
"General's Office"},
'response': {'communication_strategy': 'Public disclosure via Vermont '
"Attorney General's Office"},
'title': 'Data Breach at Next Step Healthcare, LLC',
'type': 'Data Breach'}