DisclosureLens
MisuseHealthcareProfessional ServicesHealthcarePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedPHIHealth (basic)Government IDIdentity (basic)MediumContained

Easterseals

bd_42336d78bbea1534 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 23, 2021

Filed

Jun 3, 2021

To disclose

10 weeks

Affected

Not disclosed

Confidence

67%
Full breach record for Easterseals2 incidents on file

Easterseals New Hampshire notified the NH Attorney General of a security breach involving client PHI and SSNs. Two former per diem employees accessed the EHR system after termination due to an administrative error in revoking access. Affected records included clinical notes, incident reports, and SSNs. Notices were mailed to affected individuals.

Incident timeline

discovery → filing · 10 weeks / 72 days

Mar 23, 2021

Discovered

Jun 3, 2021

Filed

vs. sector median

2 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.