Richmond Behavioral Health Authority
bd_38e8c8a165ef2012 · schema v1 · pii pii-v1
Full breach record for Richmond Behavioral Health Authority →Richmond Behavioral Health Authority (RBHA) notified the New Hampshire Attorney General on December 9, 2025, of a ransomware incident. Malicious actors accessed RBHA's network on or about September 29, 2025, and deployed ransomware on September 30, 2025. A limited set of data, including names, SSNs, passport numbers, financial account info, and health information, was potentially accessed. Approximately 4 New Hampshire residents are estimated to be affected. RBHA engaged forensic experts, notified law enforcement, terminated access, and provided Kroll identity monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 29, 2025
Begins
Sep 30, 2025
Discovered
Dec 16, 2025
Filed
vs. sector median
on median
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteqilinbd_625880881e1f603a2025-10-15 · +62dVerified
Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_3f57bc47435431fe2025-12-17 · +1dVerified by operator
- Montana State AGbd_3fce0541fd942e3c2025-12-09 · +7dVerified
- Nebraska State AGbd_202c1c93b75f1b8c2025-12-04 · +12dVerified
- Indiana State AGbd_e98cc50507d663142025-12-04 · +12dVerified
Show 1 more filing ↓Show fewer ↑up to 18d gap
- HHS OCRbd_eb9b4c55106ef3362025-11-28 · +18dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Nov 28 (VA), last Dec 17 (MA) — a 19-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.