DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPIIPHIIdentity (basic)Government IDHighContained

CATHOLIC MEDICAL CENTER

bd_383f3c0dcff9ba7a · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 20, 2023

Filed

Apr 24, 2024

To disclose

44 weeks

Affected

2,792state residents only

Linked

2 filings

Confidence

66%
Full breach record for CATHOLIC MEDICAL CENTER2 incidents on file

Catholic Medical Center (CMC) reported a security incident involving its vendor, Lamont Hanley & Associates (LH). On June 20, 2023, an LH employee email account was compromised via phishing. The investigation found that personal and health information of 2,792 CMC patients was present in the compromised account. CMC notified the NH Attorney General and affected individuals, offering credit monitoring services.

Incident timeline

discovery → filing · 44 weeks / 309 days

Jun 20, 2023

Begins

Jun 20, 2023

Discovered

Apr 24, 2024

Filed

vs. sector median

+32 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRApr 15 · first
New Hampshire State AG+9d · this page

Pattern: first filing Apr 15 (NH), last Apr 24 (NH) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.