HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIHighContained
COVENANT HEALTH
bd_5d1f9c31004b5e96 · schema v1 · pii pii-v1
Full breach record for COVENANT HEALTH →Covenant Health, Inc. notified the NH Attorney General of a data breach affecting 2,269 New Hampshire residents. Unauthorized access occurred May 18, 2025; detected May 26, 2025. Patient PII, including SSNs, names, and PHI was accessed. Covenant engaged forensic specialists, enhanced IT security, and offered 1-year Experian IdentityWorks memberships.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a41418f72b1fe371Maine State AGfiled 2025-07-11Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/covenant-health-20250711.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 11, 2025
- Raw hash
- 71689bd627b273f44324b5715c462f4052b5c7f0b7406c9d894823e4dc311276
Reporting entity
- Name
- COVENANT HEALTHnorm: covenant health
Victim entity
- Name
- COVENANT HEALTHnorm: covenant health
Incident
- Discovered
- May 26, 2025
- Materiality determined
- —
- Notification sent
- Jul 11, 2025
- Affected individuals
- 2,269
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement and appropriate agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.