AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_GOVERNMENTPIIMediumContained
Lenus
bd_5daa30d28f3bddc4 · schema v1 · pii pii-v1
Full breach record for Lenus →Lenus eHealth notified the NH Attorney General of a system error on Sept 4, 2022, that exposed SSNs of business partners in client receipts. One NH resident was affected. Lenus corrected the error, mailed notices on Sept 22, 2022, and offered 36 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lenus-ehealth-20220926.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2022
- Raw hash
- c834776c6c6fbbf8a2eec160f47c530275629fadcec0a2427a019017badca3f1
Reporting entity
- Name
- Lenusnorm: lenus
- Domain
- lenusehealth.com
Victim entity
- Name
- Lenusnorm: lenus
- Domain
- lenusehealth.com
Incident
- Discovered
- Sep 4, 2022
- Materiality determined
- —
- Notification sent
- Sep 22, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.