HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIIMediumContained
NextGen Healthcare, Inc.
bd_5e938c6c211b169d · schema v1 · pii pii-v1
Full breach record for NextGen Healthcare, Inc. →NextGen Healthcare, Inc. reported a data incident where an unknown third party gained unauthorized access to its NextGen Office system using stolen client credentials. The breach affected personal information of 1,094 New Hampshire residents between March 29 and April 14, 2023. No health records were impacted. NextGen engaged forensic experts, reset passwords, notified law enforcement, and offered 24 months of credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_67403124c4531ddcMaine State AGfiled 2023-05-05Verified
- bd_f1137d837aea9e06California State AGfiled 2023-05-05Verified
- bd_7a7f5ee7fb7c68c8Oregon State AGfiled 2023-05-04(1d gap)Verified
- bd_7e4510c6361c4a71Washington State AGfiled 2023-05-03(2d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 8d gap
- bd_03d4dffa3da1766cMontana State AGfiled 2023-04-28(7d gap)Candidate
- bd_1c6d555d72e68d6fDelaware State AGfiled 2023-04-28(7d gap)Verified
- bd_33ab8daf3c08c256Vermont State AGfiled 2023-04-27(8d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nextgen-healthcare-20230505.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2023
- Raw hash
- 7b5994d28f9532ed6cc99fb27f79831caf80a6d9cd69eee41143893880ece1d2
Reporting entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Victim entity
- Name
- NextGen Healthcare, Inc.norm: nextgen healthcare
Incident
- Discovered
- Mar 30, 2023
- Materiality determined
- —
- Notification sent
- Apr 28, 2023
- Affected individuals
- 1,094
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- contacted law enforcement and has been cooperating with them since
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.