HackingCustomer Data InvolvedDownstream VictimsPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Mental Health Association
bd_5c4598ae6e18525e · schema v1 · pii pii-v1
Full breach record for Mental Health Association →Mental Health Association, Inc. (MHA), a healthcare provider, disclosed a cybersecurity incident discovered on December 2, 2024, involving unauthorized access to systems by an external actor. The breach compromised PII and PHI, including names, addresses, SSNs, medical diagnoses, and driver's license numbers, affecting 12,633 individuals total, including 51 New Hampshire residents. MHA engaged forensic investigators, secured systems via its MSP, and offered 12 months of credit monitoring. Notification letters were mailed on May 30, 2025.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_bd376c84f8de59a7Indiana State AGfiled 2025-05-30(3d gap)Candidate
- bd_d82ca10021a228dcMaine State AGfiled 2025-05-30(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mental-health-association-20250602.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2025
- Raw hash
- ed55259481e820a68f1c34e8ec9ae12f27cc51d2470a57e68996145ecf922e8a
Reporting entity
- Name
- Mental Health Associationnorm: mental health
Victim entity
- Name
- Mental Health Associationnorm: mental health
Incident
- Discovered
- Dec 2, 2024
- Materiality determined
- May 20, 2025
- Notification sent
- May 30, 2025
- Affected individuals
- 12,633
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.