Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
UMass Memorial Health Care Master Pension Trust
bd_28661c8ab6fb77e5 · schema v1 · pii pii-v1
Full breach record for UMass Memorial Health Care Master Pension Trust →UMass Memorial Health notified the New Hampshire Attorney General of a phishing incident affecting employee email accounts. Unauthorized access occurred between June 24, 2020, and January 7, 2021. On August 25, 2021, the organization identified 17 New Hampshire residents whose PII (SSN, driver's license, financial account info) was contained in compromised emails. Total individuals notified under HIPAA was 1,370. Notifications began October 15, 2021, offering one year of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0aefe14a3374d53aMaine State AGfiled 2021-10-15Verified
- bd_162fcaf04c5a3538HHS OCRfiled 2021-10-15Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/umass-memorial-health-20211015.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2021
- Raw hash
- 8122f646453f81780349d779d36a338653aa87aa731715c2f5a3ccba7f55ff16
Reporting entity
- Name
- UMass Memorial Health Care Master Pension Trustnorm: umass memorial health care master pension
- Domain
- umassmemorial.org
Victim entity
- Name
- UMass Memorial Health Care Master Pension Trustnorm: umass memorial health care master pension
- Domain
- umassmemorial.org
Incident
- Discovered
- Aug 25, 2021
- Materiality determined
- —
- Notification sent
- Oct 15, 2021
- Affected individuals
- 17
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.