MalwareRansomwareData ExfiltratedRansom DemandedCustomer Data InvolvedDownstream VictimsIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
MCLAREN HEALTH CARE CORPORATION
bd_277031208ce9f1ec · schema v1 · pii pii-v1
Full breach record for MCLAREN HEALTH CARE CORPORATION →McLaren Health Care notified the NH AG of a ransomware attack. Unauthorized access occurred July 17–Aug 3, 2024. Discovered Aug 5, 2024. Affected 15 NH residents with PII, SSN, driver's license, and PHI. Notification sent June 20, 2025. Credit monitoring offered.
Leak gap clock✗ Leak >180d46 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
A leak claim by alphv about this victim predates this filing by 629 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_16315e097bb33c70Vermont State AGfiled 2025-06-20Verified
- bd_5ca789ddf9c80c46Indiana State AGfiled 2025-06-20Verified
- bd_e56983ab307e3088Maine State AGfiled 2025-06-20Verified
- bd_290c029e46920846HHS OCRfiled 2025-06-24(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 10d gap
- bd_1484ed8400263435Texas State AGfiled 2025-06-30(10d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mclaren-health-care-20250620.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2025
- Raw hash
- 0212101b22f473001947de0db626ec8921af9929c254875f3554c502fcd168c5
Reporting entity
- Name
- MCLAREN HEALTH CARE CORPORATIONnorm: mclaren health care
- Domain
- mclaren.org
Victim entity
- Name
- MCLAREN HEALTH CARE CORPORATIONnorm: mclaren health care
- Domain
- mclaren.org
Incident
- Discovered
- Aug 5, 2024
- Materiality determined
- May 5, 2025
- Notification sent
- Jun 20, 2025
- Affected individuals
- 15
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney GeneralProviding written notice to relevant state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 46 weeks(319 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.