MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHighContained
The Phia Group, LLC
bd_53856ef162652bd8 · schema v1 · pii pii-v1
Full breach record for The Phia Group, LLC →The Phia Group, LLC, a healthcare cost containment provider, issued a supplemental notice to the New Hampshire Attorney General regarding a July 2024 security incident. Suspicious activity disrupted network operability, and data was potentially acquired between July 8-9, 2024. The incident affected 1,433 New Hampshire residents, exposing SSNs, driver's license numbers, and financial account information. Phia engaged forensic specialists, reported to law enforcement, and provided credit monitoring via Kroll. Notifications to residents occurred between January and April 2026.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_f8a3f4c0b2d6866dCalifornia State AGfiled 2026-05-15(1d gap)Verified
- bd_c206b062995998d4South Carolina State AGfiled 2026-05-20(6d gap)Verified
- bd_466553d842bc56d4California State AGfiled 2026-01-30(104d gap)Candidate
- bd_ab77d3136d2466cdWashington State AGfiled 2026-01-30(104d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 104d gap
- bd_db0c653aaa12ad94New Hampshire State AGfiled 2026-01-30(104d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/phia-group-20260514.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2026
- Raw hash
- b1cf6f12f362197223126f6b1e175c335814148c12527e5891b10736d14d9b59
Reporting entity
- Name
- The Phia Group, LLCnorm: the phia
Victim entity
- Name
- The Phia Group, LLCnorm: the phia
Incident
- Discovered
- Jul 9, 2024
- Materiality determined
- —
- Notification sent
- Jan 28, 2026
- Affected individuals
- 1,433
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Provided supplemental notice to New Hampshire Attorney General's Office
Compliance
- Time to disclose
- 22 months(674 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.