HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Navvis & Company, LLC
bd_144ffc92b850871c · schema v1 · pii pii-v1
Full breach record for Navvis & Company, LLC →Navvis & Company, LLC, a provider of health management services, disclosed a cyber-attack where an unauthorized actor accessed systems between July 12-25, 2023. Suspicious activity was detected on July 25, 2023. The incident involved PII and PHI. Navvis notified law enforcement, HHS, and state regulators, and offered credit monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2c540e0f75fb89d3California State AGfiled 2024-06-06Candidate
- bd_7fe24140d78eee6dDelaware State AGfiled 2024-06-06Verified
- bd_e0fac2ec77d77314Vermont State AGfiled 2024-06-06Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/navvis-company-20240606.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 6, 2024
- Raw hash
- 9334dc1d778e4420c43f694b1e93818c3a6b704fbc0c6d6fd9e2ec4bbc47438f
Reporting entity
- Name
- Navvis & Company, LLCnorm: navvis
Victim entity
- Name
- Navvis & Company, LLCnorm: navvis
Incident
- Discovered
- Jul 25, 2023
- Materiality determined
- —
- Notification sent
- Sep 22, 2023
- Affected individuals
- 401
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified federal law enforcement regarding the eventprovided written notice of this incident to relevant state regulators, as necessarynotified the U.S. Department of Health and Human Services pursuant to the Health Insurance Portability and Accountability Act (HIPAA)
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 45 weeks(317 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.