HackingData ExfiltratedCustomer Data InvolvedPIIPHILowContained
Wyoming County Community Health System
bd_27eb370edf1742ce · schema v1 · pii pii-v1
Full breach record for Wyoming County Community Health System →Wyoming County Community Health System (WCCHS) notified the New Hampshire Attorney General on November 16, 2023, of a cybersecurity incident occurring on March 28, 2023. Unauthorized access to WCCHS's network resulted in the acquisition of personal and protected health information affecting 8 New Hampshire residents. WCCHS engaged third-party cybersecurity specialists, notified the FBI, and offered credit/identity protection services. No evidence of misuse was found.
Leak gap clock✗ Leak >180d33 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by nokoyawa about this victim predates this filing by 188 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_217c042e5aab0243Montana State AGfiled 2023-11-16Candidate
- bd_d793d0ba5b25f7d3Maine State AGfiled 2023-11-16Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/wyoming-county-community-health-system-20231116.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 16, 2023
- Raw hash
- b826c2dba8616aafe368acfa6b0831e3708333e849ab1eaa0c3f74ae4a3bed9a
Reporting entity
- Name
- Wyoming County Community Health Systemnorm: wyoming county community health system
- Domain
- wcchs.net
Victim entity
- Name
- Wyoming County Community Health Systemnorm: wyoming county community health system
- Domain
- wcchs.net
Incident
- Discovered
- Mar 28, 2023
- Materiality determined
- —
- Notification sent
- Nov 16, 2023
- Affected individuals
- 8
- Data types
- PIIPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 33 weeks(233 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.