HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTAUTHENTICATIONBIOMETRICPIIMediumContained
Epic
bd_3dae7362d721b95e · schema v1 · pii pii-v1
Full breach record for Epic →Epic Management LLC, a nursing home operator, notified the NH Attorney General of a data security incident discovered on September 2, 2021. An unauthorized actor accessed files in Epic's email tenant, potentially exposing PII, SSNs, health info, and financial data. Three NH residents were notified on December 14, 2022. Epic engaged forensic experts and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/epic-management-20221214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2022
- Raw hash
- 09f4e8dabbbed97acb8879be676484683c99d51648bfe35a88094927f44f7cfc
Reporting entity
- Name
- Epicnorm: epic
- Domain
- getepic.com
Victim entity
- Name
- Epicnorm: epic
- Domain
- getepic.com
Incident
- Discovered
- Sep 2, 2021
- Materiality determined
- Dec 9, 2022
- Notification sent
- Dec 14, 2022
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTAUTHENTICATIONBIOMETRICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 months(468 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.