HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedRansom DemandedIDENTITY_BASICHEALTH_BASICLowContained
INTEGRIS Health
bd_5e34203f2729eced · schema v1 · pii pii-v1
Full breach record for INTEGRIS Health →INTEGRIS Health, Inc. notified New Hampshire AG of unauthorized access to patient files on November 28, 2023. The incident involved potential access to names and health information. INTEGRIS Health engaged third-party cybersecurity specialists, notified law enforcement, and is offering credit monitoring. A group claimed responsibility on December 24, 2023. Approximately 95 Rhode Island residents were impacted.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_38004de1f0a69ec4California State AGfiled 2024-02-06Candidate
- bd_71dc05c2bcb11149Washington State AGfiled 2024-02-06Candidate
- bd_1a72e8c92bd614e4New Hampshire State AGfiled 2024-03-01(24d gap)Verified
- bd_9a9540162c4dedc2California State AGfiled 2024-03-01(24d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 49d gap
- bd_a668f84aed93d709Montana State AGfiled 2024-03-01(24d gap)Verified
- bd_4af6528e31e289b5New Hampshire State AGfiled 2024-03-26(49d gap)Verified
- bd_9429099b2e32de21California State AGfiled 2024-03-26(49d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/integris-health-20240206.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2024
- Raw hash
- 747b7f07096234792a5e409085f966100623c2fbda6edac1fe21701f73cf9c61
Reporting entity
- Name
- INTEGRIS Healthnorm: integris health
- Domain
- integrisandme.com
Victim entity
- Name
- INTEGRIS Healthnorm: integris health
- Domain
- integrisandme.com
Incident
- Discovered
- Nov 28, 2023
- Materiality determined
- —
- Notification sent
- Feb 6, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement regarding the event and is cooperating with their investigationProviding written notice of this incident to relevant state and federal regulators, as necessaryNotifying the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.