MalwareRansomwareData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Singing River Health System
bd_42a09c1a66497674 · schema v1 · pii pii-v1
Full breach record for Singing River Health System →Singing River Health System filed a supplemental notice with the New Hampshire Attorney General regarding a ransomware attack discovered on August 19, 2023. Unauthorized access occurred between August 16-18, 2023. The incident affected 19 New Hampshire residents, involving personal information. The organization engaged forensic specialists, notified law enforcement, and provided credit monitoring services to affected individuals.
Leak gap clock✗ Leak >180d38 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 246 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_892986d85f34b8d7Vermont State AGfiled 2024-05-13Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/singing-river-health-system-20240513.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2024
- Raw hash
- e3793e2571e953007e8fc5129bfea0fe083d68b1b7ac12b19c17c41b411bcb53
Reporting entity
- Name
- Singing River Health Systemnorm: singing river health system
- Domain
- singingriverhealthcare.org
Victim entity
- Name
- Singing River Health Systemnorm: singing river health system
- Domain
- singingriverhealthcare.org
Incident
- Discovered
- Aug 19, 2023
- Materiality determined
- —
- Notification sent
- May 13, 2024
- Affected individuals
- 19
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- notified federal law enforcement regarding the eventproviding written notice of this incident to relevant state and federal regulators, as necessary, and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
Compliance
- Time to disclose
- 38 weeks(268 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.