HackingStolen CredentialsPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Comprehensive Health Services
bd_119a2929b9bc9c2b · schema v1 · pii pii-v1
Full breach record for Comprehensive Health Services →Comprehensive Health Services (CHS) notified the New Hampshire Attorney General on February 15, 2022, regarding a data security incident affecting 427 NH residents. CHS detected unusual activity on September 30, 2020, following fraudulent wire transfers. Investigation concluded November 3, 2021, revealing unauthorized access to invoicing files containing names and SSNs of a customer's employees. CHS engaged forensic experts, notified the FBI, and offered credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_71314889a3bf0e51New Hampshire State AGfiled 2022-01-20(26d gap)Verified
- bd_3287d556e934a6bdNew Hampshire State AGfiled 2022-03-15(28d gap)Verified
- bd_7b6e34bd70633badMaine State AGfiled 2022-03-16(29d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/comprehensive-health-services-20220215.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2022
- Raw hash
- ddbe947ba53cd1adcdfa29a66f4b02c7dcadb122f94d715fdc1991aeef5f9c27
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
Incident
- Discovered
- Sep 30, 2020
- Materiality determined
- —
- Notification sent
- Feb 15, 2022
- Affected individuals
- 427
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(503 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.