AccidentalLossSupply Chain (3P Vendor)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
LRGHealthcare
bd_364ccad7ab3b9557 · schema v1 · pii pii-v1
Full breach record for LRGHealthcare →LRGHealthcare notified the New Hampshire Attorney General on December 19, 2008, regarding a potential disclosure of Personal Health Information (PHI). A package containing patient payment records, sent by third-party provider Lighthouse Financial Services, was lost by UPS. Approximately 1,500 patients were potentially affected. The data included names, DOBs, diagnoses, procedure codes, and financial account details. LRGHealthcare notified credit bureaus and sent individual letters advising fraud alerts.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,500 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lrghealthcare-20081219.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2008
- Raw hash
- e187ecfeb290674b39d46a9ab353b5812628f5862176068972686d866fef28aa
Reporting entity
- Name
- LRGHealthcarenorm: lrghealthcare
- Domain
- lrgh.org
Victim entity
- Name
- LRGHealthcarenorm: lrghealthcare
- Domain
- lrgh.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 19, 2008
- Affected individuals
- 1,500
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Partner
- Regulator citations
- Notified New Hampshire Assistant Attorney General Noether, Bureau Chief, Consumer Protection
- Third party
- via Lighthouse Financial Services
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.