DisclosureLens
HackingHealthcareHealthcareData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountMediumContained

Operation PAR, Inc, Boley Centers, Inc. and PEMHS

bd_31b2ab732e37a81a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 10, 2026

Filed

Jun 29, 2026

To disclose

19 days

Affected

65state residents only

Confidence

66%
Full breach record for Operation PAR, Inc, Boley Centers, Inc. and PEMHS2 incidents on file

Operation PAR, Inc., Boley Centers, Inc., and PEMHS dba Eleos notified the New Hampshire Attorney General of a cybersecurity incident affecting 65 New Hampshire residents. Unauthorized access occurred between June 6, 2025, and June 10, 2025. Impacted data included names, DOB, driver's license numbers, health insurance info, and SSNs. The entities engaged external cybersecurity professionals, secured the network, and offered one year of credit monitoring to affected residents. Notification was sent on June 25, 2026.

Incident timeline

undetected · 369 days
discovery → filing · 19 days

Jun 6, 2025

Begins

Jun 10, 2026

Discovered

Jun 29, 2026

Filed

vs. sector median

10 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed65 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.