DisclosureLens
Social EngineeringHealthcareHealthcarePhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryGovernment IDIdentity (basic)Financial accountHighContained

UMass Memorial Health Care, Inc.

bd_28661c8ab6fb77e5 · schema v1 · pii pii-v1

Severity

High

Discovered

Aug 25, 2021

Filed

Oct 15, 2021

To disclose

7 weeks

Affected · nationwide

1,37017 in this filing

Linked

4 filings

Confidence

66%
Full breach record for UMass Memorial Health Care, Inc.9 incidents on file

UMass Memorial Health notified the New Hampshire Attorney General of a phishing incident affecting employee email accounts. Unauthorized access occurred between June 24, 2020, and January 7, 2021. On August 25, 2021, the organization identified 17 New Hampshire residents whose PII (SSN, driver's license, financial account info) was contained in compromised emails. Total individuals notified under HIPAA was 1,370. Notifications began October 15, 2021, offering one year of credit monitoring.

Incident timeline

undetected · 427 days
discovery → filing · 7 weeks / 51 days

Jun 24, 2020

Begins

Aug 25, 2021

Discovered

Oct 15, 2021

Filed

vs. sector median

4 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 3 states

View merged incident ↗
Maine State AGOct 15 · first
Massachusetts State AGOct 15 · first
HHS OCROct 15 · first
New Hampshire State AGOct 15 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.