HackingCustomer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Watson Clinic
bd_12afd948062e2141 · schema v1 · pii pii-v1
Full breach record for Watson Clinic →Watson Clinic notified New Hampshire AG of a cybersecurity incident where an unauthorized third party gained access to portions of its network starting January 26, 2024, discovered on February 6, 2024. The incident potentially exposed personal information and protected health information (including diagnoses and medical record numbers) of patients. Watson Clinic engaged third-party experts and offered credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6f0e8b5375883365Montana State AGfiled 2024-08-26Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/watson-clinic-20240826.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 26, 2024
- Raw hash
- 12f445a7f669d34b68f88a44191de58b25aadcfc81c261cc517a9d8ae61362e7
Reporting entity
- Name
- Watson Clinicnorm: watson clinic
Victim entity
- Name
- Watson Clinicnorm: watson clinic
Incident
- Discovered
- Feb 6, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 weeks(202 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.