HackingIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Capital Region Medical Center
bd_32f439e24ceb5bee · schema v1 · pii pii-v1
Full breach record for Capital Region Medical Center →Capital Region Medical Center (CRMC) notified the New Hampshire Attorney General of a cybersecurity incident on March 25, 2022. The incident occurred on December 17, 2021, when an unauthorized third party gained access to files containing personal and health information of 4 New Hampshire residents. Data exposed included names, DOB, addresses, medical info, SSNs, and driver's license numbers. CRMC disabled its network, engaged forensic and data review firms, and notified law enforcement. Credit monitoring was offered to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/capital-region-medical-center-20220325.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2022
- Raw hash
- fb3353eb3248da235bfe190f9cae48e102ca562c17b18b56a174f35e7f0c04fc
Reporting entity
- Name
- Capital Region Medical Centernorm: capital region medical center
- Domain
- crmc.org
Victim entity
- Name
- Capital Region Medical Centernorm: capital region medical center
- Domain
- crmc.org
Incident
- Discovered
- Dec 17, 2021
- Materiality determined
- —
- Notification sent
- Mar 24, 2022
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified the public via CRMC’s Facebook page and media reportingnotified the New Hampshire Attorney General's Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.