HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NewGen Administrative Services, LLC
bd_14ff22bcc679e741 · schema v1 · pii pii-v1
Full breach record for NewGen Administrative Services, LLC →NewGen Administrative Services, LLC notified the New Hampshire Attorney General of a security incident involving a third-party managed services provider. On or about September 13, 2023, the provider detected potential unauthorized access to servers hosting data for NewGen and its clients (Windsor care centers). NewGen could not confirm what specific information was accessed. Out of caution, 6 New Hampshire residents were notified. Response included credit monitoring via TransUnion and regulatory notifications to HHS and credit bureaus.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2e4ec69fe50511d9Montana State AGfiled 2024-02-23Candidate
- bd_8993377c2d64d768California State AGfiled 2024-02-23Verified
- bd_b3ca00b1300996c1Indiana State AGfiled 2024-02-23Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/newgen-administrative-services-20240223.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2024
- Raw hash
- 70fbefc4578daba2dc3ceefe5582d6c90d538f820218bfe9b7f2dde3b1be721e
Reporting entity
- Name
- NewGen Administrative Services, LLCnorm: newgen administrative
Victim entity
- Name
- NewGen Administrative Services, LLCnorm: newgen administrative
Incident
- Discovered
- Sep 13, 2023
- Materiality determined
- —
- Notification sent
- Feb 23, 2024
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Notifying the U.S. Department of Health and Human Services and prominent media pursuant to the Health Insurance Portability and Accountability Act (HIPAA)Provided written notice of this incident to relevant state and federal regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.