HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumActive
Healthcare
bd_70260a8e76e0307d · schema v1 · pii pii-v1
Full breach record for Healthcare →Healthcare Interactive, Inc. (HCIactive) notified the New Hampshire Attorney General on December 3, 2025, of a data event affecting 764 NH residents. Unauthorized access occurred between July 8-12, 2025, when an actor copied files containing PII, PHI, and financial data. HCIactive discovered suspicious activity on July 22, 2025. Response included notifying law enforcement, HIPAA, and offering one year of credit monitoring.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_6abe8471281b13c9California State AGfiled 2025-12-04Verified
- bd_f2bc4b14a0bb937cTexas State AGfiled 2025-12-05(1d gap)Verified
- bd_24e627b87c7f7770Montana State AGfiled 2025-12-03(1d gap)Candidate
- bd_2f93d58752934b0fDelaware State AGfiled 2025-12-02(2d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 34d gap
- bd_dc7a379ed18a2f4bIndiana State AGfiled 2025-12-02(2d gap)Verified
- bd_f7ff890940575fffVermont State AGfiled 2025-12-02(2d gap)Verified
- bd_3fb448554080b067Iowa State AGfiled 2026-01-07(34d gap)Verified
- bd_c26c4bb7875814e3South Carolina State AGfiled 2026-01-07(34d gap)Verified
- bd_e618981a846f7f18Oregon State AGfiled 2026-01-07(34d gap)Verified
- bd_ea0e211988dbadb8Washington State AGfiled 2026-01-07(34d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/healthcare-interactive-20251204.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 4, 2025
- Raw hash
- 143dff7a4b97f4aa6bb0cda87d240952b5faf3040c658b0fd2f0911c557609f0
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Healthcarenorm: healthcare
- Domain
- healthcare.ascension.org
Incident
- Discovered
- Jul 22, 2025
- Materiality determined
- —
- Notification sent
- Dec 3, 2025
- Affected individuals
- 764
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified the U.S. Department of Health and Human Services pursuant to the Health Insurance Portability and Accountability Act (HIPAA)Providing written notice of this incident to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.