RGH Enterprises, Inc.
bd_526b639a12369691 · schema v1 · pii pii-v1
Full breach record for RGH Enterprises, Inc. →4 incidents on fileRGH Enterprises, Inc. d/b/a Edgepark Medical Supplies notified the NH Attorney General of a security event affecting 26 NH residents. Hackers exploited a vulnerability in Adobe Coldfusion on the company's web server between March 9-11, 2013, installing malware that intercepted online account usernames and passwords. The malware was discovered on December 12, 2013. Affected data included names, dates of birth, addresses, phone numbers, email addresses, partial credit card information, and for one individual, full credit card numbers. Health information including diagnoses, primary physicians, and order history was also potentially accessible. The company removed the malware, reset passwords, and offered 12 months of identity protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 9, 2013
Begins
Dec 12, 2013
Discovered
Jan 10, 2014
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_649f04e8679eb6bb2014-01-13 · +3dCandidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.