Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Centerstone of Tennessee, Inc.
bd_50e662acc1130a18 · schema v1 · pii pii-v1
Full breach record for Centerstone of Tennessee, Inc. →Centerstone of Tennessee, Inc. notified the New Hampshire Attorney General of a data security incident involving one NH resident. Unauthorized access to an employee email account occurred on January 8, 2022, likely via phishing. The breach exposed names and Social Security numbers. Centerstone discovered the activity on February 14, 2022, and notified the resident on September 12, 2022. Remediation included credential resets, policy revisions, and offering 12 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b9106ab9b1c0f8d3Montana State AGfiled 2022-09-14(1d gap)Candidate
- bd_d5fb12ad38bb3a0bHHS OCRfiled 2022-09-12(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/centerstone-tennessee-20220915.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2022
- Raw hash
- 9b43f6edca19c0da82c6c4d54fd6267268ad7ab59d56adf1a52e1ac8fc41a57a
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Centerstone of Tennessee, Inc.norm: centerstone of tennessee
Incident
- Discovered
- Feb 14, 2022
- Materiality determined
- —
- Notification sent
- Sep 12, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to the Department of Health and Human Services Office for Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 30 weeks(213 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.