DisclosureLens
HackingHealthcareProfessional ServicesHealthcareStolen CredentialsPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryGovernment IDIdentity (basic)MediumContained

Comprehensive Health Services

bd_119a2929b9bc9c2b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 30, 2020

Filed

Feb 15, 2022

To disclose

17 months

Affected

427state residents only

Linked

9 filings

Confidence

67%
Full breach record for Comprehensive Health Services7 incidents on file

Comprehensive Health Services (CHS) notified the New Hampshire Attorney General on February 15, 2022, regarding a data security incident affecting 427 NH residents. CHS detected unusual activity on September 30, 2020, following fraudulent wire transfers. Investigation concluded November 3, 2021, revealing unauthorized access to invoicing files containing names and SSNs of a customer's employees. CHS engaged forensic experts, notified the FBI, and offered credit monitoring.

Incident timeline

discovery → filing · 17 months / 503 days

Sep 30, 2020

Discovered

Feb 15, 2022

Filed

vs. sector median

+59 wks slower

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 29d gap

Filing propagation · 9 filings · 6 states

View merged incident ↗

Pattern: first filing Jan 20 (NH), last Mar 16 (ME) — a 55-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.