HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPHIMediumActive
Shields Health Care Group, Inc.
bd_4ce30febe6d1e83d · schema v1 · pii pii-v1
Full breach record for Shields Health Care Group, Inc. →Shields Health Care Group, Inc. notified the New Hampshire Attorney General on June 10, 2022, of a data event affecting New Hampshire residents. An unknown actor accessed Shields systems between March 7 and March 21, 2022. Shields became aware of suspicious activity on March 28, 2022. The incident involved the exfiltration of PHI and PII, including SSNs, names, and DOB. Substituted notice was provided on May 27, 2022. The investigation and data review remain ongoing.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6323f931092b3aa8Maine State AGfiled 2022-07-22(38d gap)Verified
- bd_6858fa9ec9086f9eMaine State AGfiled 2023-04-19(309d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/shields-health-care-20220614.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 14, 2022
- Raw hash
- d72dce8dfcfa9cf967e64fa27f7244bfd3bff68108ecb047999fd3ebb91647b4
Reporting entity
- Name
- Shields Health Care Group, Inc.norm: shields health care
- Domain
- shields.com
Victim entity
- Name
- Shields Health Care Group, Inc.norm: shields health care
- Domain
- shields.com
Incident
- Discovered
- Mar 28, 2022
- Materiality determined
- —
- Notification sent
- May 27, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementReported this incident to relevant state and federal regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.