HackingSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
CRG Lynwood, LLC
bd_605c836d0f7905f0 · schema v1 · pii pii-v1
Full breach record for CRG Lynwood, LLC →CRG Lynwood, LLC d/b/a Lynwood Manor notified the NH AG of a cybersecurity incident involving its third-party administrator, Excelerate Healthcare Services (EHS). The incident occurred in July 2021, but Lynwood did not learn of the potential impact on patient information until September 2022. The breach exposed PII, including names and addresses. Lynwood engaged forensic investigators, deployed monitoring tools, and offered credit monitoring services to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_807a36cceac76c0cMaine State AGfiled 2024-06-10Verified
- bd_9e946490177e4566HHS OCRfiled 2024-06-10Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/crg-lynwood-manor-20240610.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2024
- Raw hash
- 41c182c51ff72f8a8bba93daa20e4cb8d6444d8f33c331a85ce6e4f0b946f729
Reporting entity
- Name
- CRG Lynwood, LLCnorm: crg lynwood
Victim entity
- Name
- CRG Lynwood, LLCnorm: crg lynwood
Incident
- Discovered
- Sep 1, 2022
- Materiality determined
- —
- Notification sent
- Jun 7, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 months(648 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.