Mental Health Association
bd_5c4598ae6e18525e · schema v1 · pii pii-v1
Full breach record for Mental Health Association →2 incidents on fileMental Health Association, Inc. (MHA), a healthcare provider, disclosed a cybersecurity incident discovered on December 2, 2024, involving unauthorized access to systems by an external actor. The breach compromised PII and PHI, including names, addresses, SSNs, medical diagnoses, and driver's license numbers, affecting 12,633 individuals total, including 51 New Hampshire residents. MHA engaged forensic investigators, secured systems via its MSP, and offered 12 months of credit monitoring. Notification letters were mailed on May 30, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2024
Discovered
May 20, 2025
Scope determined
Jun 2, 2025
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_8c83ae51403c21282025-05-30 · +3dVerified
- Indiana State AGbd_bd376c84f8de59a72025-05-30 · +3dCandidate
- Maine State AGbd_d82ca10021a228dc2025-05-30 · +3dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.