HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
HIGH POINT TREATMENT CENTER, INC.
bd_612ba6f390f521fd · schema v1 · pii pii-v1
Full breach record for HIGH POINT TREATMENT CENTER, INC. →High Point Treatment Center, Inc. notified the New Hampshire Attorney General of a cybersecurity event discovered on July 6, 2025. Unauthorized access resulted in the viewing and copying of patient/employee names, Social Security numbers, and dates of birth. 15 New Hampshire residents were notified. High Point engaged forensic investigators, reset passwords, and provided 24 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_f980f192f224c84eLeak Siteabyssfiled 2025-07-26(10d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_b3de2cc3596517b8Maine State AGfiled 2025-07-29(7d gap)Verified
- bd_b9e7bee38cf6f463HHS OCRfiled 2026-01-30(178d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/high-point-treatment-center-20250805.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 5, 2025
- Raw hash
- d6c3253d983031f89cefb95bc62fe9462839b48fc135f6fe4ae2e13d65532cbe
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- HIGH POINT TREATMENT CENTER, INC.norm: high point treatment center
- Domain
- hptc.org
Incident
- Discovered
- Jul 6, 2025
- Materiality determined
- —
- Notification sent
- Jul 29, 2025
- Affected individuals
- 15
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.