HackingVulnerability ExploitStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Nacogdoches Memorial Hospital
bd_10c07a29e1f5befd · schema v1 · pii pii-v1
Full breach record for Nacogdoches Memorial Hospital →Nacogdoches Memorial Hospital reported a cybersecurity incident to the New Hampshire Attorney General on March 31, 2026. The hospital became aware of the unauthorized access to its network on January 31, 2026. The breach potentially exposed patient information, including names, addresses, SSNs, dates of birth, and medical records. Two New Hampshire residents were notified. The hospital engaged law enforcement, reset credentials, and enhanced network security.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_532a9f2d9cbd8c1aMaine State AGfiled 2026-03-31Verified
- bd_e894e0dd4e632bf3HHS OCRfiled 2026-03-30(1d gap)Verified
- bd_ba4426b59fd205cdIndiana State AGfiled 2026-03-12(19d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nacogdoches-memorial-hospital-20260331.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2026
- Raw hash
- a7fe59eece6648d2c39c79fdb50b6a6ce48e81b7e0ec2d83d436fde099899848
Reporting entity
- Name
- Nacogdoches Memorial Hospitalnorm: nacogdoches memorial hospital
- Domain
- nacmem.org
Victim entity
- Name
- Nacogdoches Memorial Hospitalnorm: nacogdoches memorial hospital
- Domain
- nacmem.org
Incident
- Discovered
- Jan 31, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.