AccidentalMisconfigurationSupply Chain (3P Vendor)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Unicare Health Services
bd_144a767a082af0ad · schema v1 · pii pii-v1
Full breach record for Unicare Health Services →UniCare notified the New Hampshire Attorney General of a security breach involving a third-party vendor. A server containing Protected Health Information (PHI) was improperly secured, making member IDs, SSNs, and pharmacy/medical data accessible via the internet. Approximately 4 New Hampshire residents were affected. UniCare secured the data, notified affected members, and offered one year of credit monitoring through Equifax.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/unicare-20080402.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2008
- Raw hash
- 20f35e0aef025695b50d9b08e1b1e6a4673aa16a694f0e32441b6b6b1b2a26b6
Reporting entity
- Name
- Hinman Straubnorm: hinman straub
- Domain
- hinmanstraub.com
Victim entity
- Name
- Unicare Health Servicesnorm: unicare health
- Domain
- unicareusa.com
Incident
- Discovered
- Apr 2, 2007
- Materiality determined
- —
- Notification sent
- Apr 4, 2008
- Affected individuals
- 4
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Notified New Hampshire Attorney General Kelly A. Ayotte
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 months(366 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.