Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIPHIIDENTITY_BASICMediumContained
CATHOLIC MEDICAL CENTER
bd_383f3c0dcff9ba7a · schema v1 · pii pii-v1
Full breach record for CATHOLIC MEDICAL CENTER →Lamont Hanley & Associates, a third-party vendor contracted by Catholic Medical Center for accounts receivable services, notified CMC on March 6, 2024, of a phishing incident potentially exposing personal and health information of 2,792 patients. Catholic Medical Center filed this initial breach notification with the New Hampshire Attorney General on April 24, 2024. Credit monitoring was offered to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c28b6497085a292dHHS OCRfiled 2024-04-15(9d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/catholic-medical-center-lamont-hanley-20240424.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 24, 2024
- Raw hash
- 220c0f31aecd8f46287624a629ce9fc3a6881006ed000ba82f7eddc141374f65
Reporting entity
- Name
- Lamont Hanley & Associates, Inc.norm: lamont hanley associates
Victim entity
- Name
- CATHOLIC MEDICAL CENTERnorm: catholic medical center
Incident
- Discovered
- Mar 6, 2024
- Materiality determined
- —
- Notification sent
- Apr 24, 2024
- Affected individuals
- 2,792
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.