HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Bridges Hospice
bd_64e4f040a8df019c · schema v1 · pii pii-v1
Full breach record for Bridges Hospice →Bridges Experience, Inc. notified the NH AG that unauthorized parties accessed employee email accounts between Dec 2, 2024 and Jan 22, 2025. The breach exposed NH residents' names, DOBs, SSNs, and limited medical/insurance info. Bridges EXP engaged cybersecurity professionals, contained the incident, and offered 1 year of Equifax credit monitoring to 149 affected residents.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1ef98a8f5a0c9efaTexas State AGfiled 2025-07-01(1d gap)Verified
- bd_0da26962cbbba4c6Delaware State AGfiled 2025-06-26(4d gap)Verified
- bd_12807c4a6d92e71bOregon State AGfiled 2025-06-26(4d gap)Candidate
- bd_1449f67808f2bce5Vermont State AGfiled 2025-06-26(4d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 4d gap
- bd_229a42b3a6021fc6Indiana State AGfiled 2025-06-26(4d gap)Verified
- bd_3db6a39547dc7f08Montana State AGfiled 2025-06-26(4d gap)Verified by operator
- bd_4a3806f82b493cfaCalifornia State AGfiled 2025-06-26(4d gap)Verified
- bd_55d07a6af1f99a5cWashington State AGfiled 2025-06-26(4d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bridges-experience-20250630.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2025
- Raw hash
- 8b447821633e294c094bb3c9e561cdaf54d9d802a33cdf584ec07af12129a695
Reporting entity
- Name
- Bridges Hospicenorm: bridges hospice
- Domain
- bridgeshospice.org
Victim entity
- Name
- Bridges Hospicenorm: bridges hospice
- Domain
- bridgeshospice.org
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- Jun 26, 2025
- Affected individuals
- 149
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.