HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NextGen Healthcare, Inc.
bd_1c6d555d72e68d6f · schema v1 · pii pii-v1
Full breach record for NextGen Healthcare, Inc. →NextGen Healthcare, Inc. notified patients of a data incident involving unauthorized access to the NextGen Office system between March 29 and April 14, 2023. The breach exposed personal information including names, dates of birth, addresses, and Social Security numbers. No health or medical records were accessed. NextGen engaged forensic experts, reset passwords, contacted law enforcement, and offered 24 months of identity theft protection via Experian.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_03d4dffa3da1766cMontana State AGfiled 2023-04-28Candidate
- bd_33ab8daf3c08c256Vermont State AGfiled 2023-04-27(1d gap)Verified
- bd_7e4510c6361c4a71Washington State AGfiled 2023-05-03(5d gap)Verified
- bd_7a7f5ee7fb7c68c8Oregon State AGfiled 2023-05-04(6d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 7d gap
- bd_5e938c6c211b169dNew Hampshire State AGfiled 2023-05-05(7d gap)Verified
- bd_67403124c4531ddcMaine State AGfiled 2023-05-05(7d gap)Verified
- bd_f1137d837aea9e06California State AGfiled 2023-05-05(7d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/05/NextGen-Notification-Letter-Individual-FINAL.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 28, 2023
- Raw hash
- f788092d834424fdd6d4ac6c59c496bc34c02e3220bbffdc3a9d0f01baa99d14
Reporting entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Victim entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Incident
- Discovered
- Mar 30, 2023
- Materiality determined
- —
- Notification sent
- Apr 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- contacted law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.