HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Warren General Hospital
bd_0093aa35975521df · schema v1 · pii pii-v1
Full breach record for Warren General Hospital →Warren General Hospital notified New Hampshire residents of a data breach where an unknown actor accessed systems between Sept 15-23, 2023, downloading patient and employee data including SSNs, financial info, and medical records. 69 NH residents were notified on Nov 17, 2023. The hospital engaged forensic specialists, reported to federal law enforcement, and offered credit monitoring.
Leak gap clock⏱ Leak >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by ransomhouse about this victim predates this filing by 55 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1924dfe0062bd3f1Vermont State AGfiled 2023-11-17Verified
- bd_d03a06da70bd116fHHS OCRfiled 2023-11-09(8d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/warren-general-hospital-20231117.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2023
- Raw hash
- 6a1b16a44b32eddf460aa6ef5c3ae0fd64f53e71a412d42bc38b4471bcfefb0b
Reporting entity
- Name
- Warren General Hospitalnorm: warren general hospital
- Domain
- wgh.org
Victim entity
- Name
- Warren General Hospitalnorm: warren general hospital
- Domain
- wgh.org
Incident
- Discovered
- Sep 24, 2023
- Materiality determined
- —
- Notification sent
- Nov 17, 2023
- Affected individuals
- 69
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- provided initial notice of this event to the U.S. Department of Health and Human Servicesprovided supplemental notice to the U.S. Department of Health and Human Servicesprovided written notice to appropriate state privacy regulatorsprovided written notice to the three major consumer reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.