CITY OF HOPE
bd_4e34f10272b1cbb2 · schema v1 · pii pii-v1
Full breach record for CITY OF HOPE →City of Hope, a cancer treatment and research organization, notified the New Hampshire Attorney General on April 2, 2024, of a data breach affecting approximately 181 NH residents. Unauthorized access occurred between September 19 and October 12, 2023. The incident involved the exfiltration of personal and health information, including names, medical record numbers, and potentially government IDs. City of Hope engaged forensic investigators, reported to law enforcement, and offered credit monitoring to affected individuals. The investigation was ongoing at the time of filing.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_512fd9d9da2e106bMontana State AGfiled 2024-04-02Candidate
- bd_56c727d6f5a7adc5Vermont State AGfiled 2024-04-02Verified
- bd_646c0dd6c4c8efeeCalifornia State AGfiled 2024-04-02Verified
- bd_a206c1ef5bf16daeWashington State AGfiled 2024-04-02Verified
Show 3 more filings ↓Show fewer ↑up to 14d gap
- bd_eacec21685bd1ec2Maine State AGfiled 2024-04-02Verified
- bd_9a6d405cfd05175cOregon State AGfiled 2024-04-03(1d gap)Verified
- bd_2b407412ec00741dOregon State AGfiled 2024-04-16(14d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/city-hope-20240402.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2024
- Raw hash
- 115461df1feb4fa8b1057807d321e6763b7c523ac698da4bd8acde531fd2489e
Reporting entity
- Name
- CITY OF HOPEnorm: city of hope
- Domain
- cityofhope.org
Victim entity
- Name
- CITY OF HOPEnorm: city of hope
- Domain
- cityofhope.org
Incident
- Discovered
- Oct 13, 2023
- Materiality determined
- —
- Notification sent
- Apr 2, 2024
- Affected individuals
- 181
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to law enforcementnotified regulatory bodies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.