HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumActive
Mount Desert Island Hospital
bd_044b7cb6e8c5de74 · schema v1 · pii pii-v1
Full breach record for Mount Desert Island Hospital →Mount Desert Island Hospital, Inc. notified the NH AG of a data security incident. Unauthorized access occurred between April 28 and May 7, 2023. MDIH became aware on May 4, 2023. The investigation is ongoing. Impacted data includes names combined with SSNs or health info for employees, dependents, beneficiaries, and patients. Law enforcement was notified. IDX Identity Monitoring was offered.
Leak gap clock⏱ Leak >30d10 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 41 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_d67d09f2ab8c5b20Montana State AGfiled 2023-07-14Candidate
- bd_437493e24886ba99Maine State AGfiled 2023-07-17(3d gap)Verified
- bd_529604a4efb3f8f5Vermont State AGfiled 2023-06-30(14d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mount-desert-island-hospital-20230714.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2023
- Raw hash
- 7c56b67924099b3b7f4e11f8f83227b882c85beabaec9e78661bf3257ead24f3
Reporting entity
- Name
- Mount Desert Island Hospitalnorm: mount desert island hospital
- Domain
- mdihospital.org
Victim entity
- Name
- Mount Desert Island Hospitalnorm: mount desert island hospital
- Domain
- mdihospital.org
Incident
- Discovered
- May 4, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.