HackingStolen CredentialsCapture Stored DataCustomer Data InvolvedData ExfiltratedIDENTITY_BASICLowContained
Carolina Arthritis
bd_25b183630cee6006 · schema v1 · pii pii-v1
Full breach record for Carolina Arthritis →Carolina Arthritis Associates, a rheumatology practice, notified the NH AG of a data security incident on Feb 27, 2025. Unauthorized access occurred on Sept 27, 2024, affecting personal information of 4 NH residents. The company engaged cybersecurity experts and offered identity protection services.
Leak gap clock⏱ Leak >90d22 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
A leak claim by threeam about this victim predates this filing by 125 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_afad31b5e423fe58Leak Sitethreeamfiled 2024-10-24(125d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_3e3faec2dc9622c0Maine State AGfiled 2025-02-27Verified
- bd_47d1979d018b1d02HHS OCRfiled 2025-02-27Verified
- bd_5c4c73fe34204471Vermont State AGfiled 2025-02-27Verified
- bd_7f5415b879da3317Indiana State AGfiled 2025-02-27Verified
Show 1 more filing ↓Show fewer ↑
- bd_8076b43f1a07995dMaryland State AGfiled 2025-02-27Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/carolina-arthritis-20250227.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- d28727402ebca4edf15d2698644e126bb8ad252e9a0220d3e40d533f972564c9
Reporting entity
- Name
- Carolina Arthritisnorm: carolina arthritis
- Domain
- carolinaarthritis.com
Victim entity
- Name
- Carolina Arthritisnorm: carolina arthritis
- Domain
- carolinaarthritis.com
Incident
- Discovered
- Sep 27, 2024
- Materiality determined
- Jan 21, 2025
- Notification sent
- Feb 27, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.