HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Goshen Medical Center
bd_4f1a0667685dff01 · schema v1 · pii pii-v1
Full breach record for Goshen Medical Center →Goshen Medical Center notified the New Hampshire Attorney General of a data security incident affecting approximately 30 NH residents. Unauthorized access to files occurred on February 15, 2025, detected on March 4, 2025. Data involved included names, addresses, DOBs, SSNs, driver's license numbers, and medical record numbers. GMC engaged cybersecurity specialists, provided 12 months of credit monitoring, and implemented additional employee safeguards.
Leak gap clock✗ Leak >180d28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by bianlian about this victim predates this filing by 214 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_87bc6b8ceac856f3Indiana State AGfiled 2025-09-17Verified
- bd_97e80ec997b73cd9HHS OCRfiled 2025-09-17Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/goshen-medical-center-20250917.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 17, 2025
- Raw hash
- 0ee1a362970976d85dc6f0205c30110cf4719a1eb90fe4aa11edf2d02774f43b
Reporting entity
- Name
- Goshen Medical Centernorm: goshen medical center
- Domain
- goshenmedical.org
Victim entity
- Name
- Goshen Medical Centernorm: goshen medical center
- Domain
- goshenmedical.org
Incident
- Discovered
- Mar 4, 2025
- Materiality determined
- —
- Notification sent
- Sep 17, 2025
- Affected individuals
- 30
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 28 weeks(197 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.