HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPHIIDENTITY_BASICLowContained
Menorah Life
bd_6bc356cbf340bb5c · schema v1 · pii pii-v1
Full breach record for Menorah Life →Menorah Life, a senior healthcare organization, notified the NH AG of a data security incident involving PHI of 2 NH residents. Unauthorized access occurred June 27-July 22, 2024, via compromised credentials at third-party vendor PointClickCare. Menorah Life was notified on Sept 19, 2024. Notices were sent Jan 29, 2025, offering credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/menorah-life-20250205.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2025
- Raw hash
- 28a65ff61c767a65a25491fb5d832a195d9b35db7a5042acbdddb0bfea647b62
Reporting entity
- Name
- Menorah Lifenorm: menorah life
- Domain
- menorahlife.org
Victim entity
- Name
- Menorah Lifenorm: menorah life
- Domain
- menorahlife.org
Incident
- Discovered
- Sep 19, 2024
- Materiality determined
- —
- Notification sent
- Jan 29, 2025
- Affected individuals
- 2
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to the Department of Health and Human Services Office of Civil Rights
- Third party
- via PointClickCare
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(139 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.