Capital Region Medical Center
bd_32f439e24ceb5bee · schema v1 · pii pii-v1
Full breach record for Capital Region Medical Center →Capital Region Medical Center (CRMC) experienced a cybersecurity incident on December 17, 2021, where an unauthorized third party gained access to files containing personal and health information of patients and employees. The incident affected four New Hampshire residents. Data exposed included names, dates of birth, addresses, medical information, health insurance information, and potentially Social Security and driver's license numbers. CRMC disabled its network, engaged forensic investigators, and notified law enforcement. Credit monitoring was offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 17, 2021
Begins
Dec 17, 2021
Discovered
Mar 25, 2022
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_9adc7a8104cf5c602022-03-25Verified
- Montana State AGbd_c8480a3cbc771a482022-03-25Verified
- Indiana State AGbd_6299b52aa0fbf0cf2022-03-24 · +1dVerified by operator
- Massachusetts State AGbd_e52487bfa623bfbc2022-03-30 · +5dCandidate
Show 1 more filing ↓Show fewer ↑up to 14d gap
- HHS OCRbd_7ab7349dfcd1fd472022-03-11 · +14dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Mar 11 (MO), last Mar 30 (MA) — a 19-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.