HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
SysInformation Healthcare Services, Inc.
bd_502dadec6642b714 · schema v1 · pii pii-v1
Full breach record for SysInformation Healthcare Services, Inc. →SysInformation Healthcare Services, LLC reported a supplemental data event to the NH AG. Unauthorized access occurred June 3-18, 2023. Suspicious activity discovered in June 2023. Incident involved PII, PHI, and financial data of healthcare clients' individuals. 2 NH residents and ~1,394 RI residents affected. Credit monitoring offered.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0b78b46cfff5cc8dVermont State AGfiled 2024-10-29Verified
- bd_0fdbad83d099a492California State AGfiled 2024-10-29Verified
- bd_4e3382893d03266fMaine State AGfiled 2024-10-29Verified
- bd_b6be72836a476f89Maine State AGfiled 2024-10-10(19d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sysinformation-healthcare-equalizercm-1st-credentialing-20241029.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 29, 2024
- Raw hash
- 76f1118cc4dd7e080d6b7c3048bf014afa12ca76f2fb0308cd38b6ebc75266c1
Reporting entity
- Name
- SysInformation Healthcare Services, Inc.norm: sysinformation healthcare
- Domain
- sysinformation.com
Victim entity
- Name
- SysInformation Healthcare Services, Inc.norm: sysinformation healthcare
- Domain
- sysinformation.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 27, 2024
- Affected individuals
- 1,394
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to law enforcement and regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(516 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.