AccidentalMisconfigurationCustomer Data InvolvedData ExfiltratedPIIPHIIDENTITY_BASICLowContained
Serviceaide, Inc.
bd_717e1def22e0fbf1 · schema v1 · pii pii-v1
Full breach record for Serviceaide, Inc. →Serviceaide, Inc. notified the New Hampshire AG of a data event affecting 32 NH residents. Patient information in its Catholic Health database was inadvertently made publicly available between Sept 19 and Nov 5, 2024. Serviceaide discovered the incident on Nov 15, 2024, secured the database, and engaged a vendor for data review. No evidence of copying was found, but exfiltration could not be ruled out. Notices were sent to residents and regulators on May 9, 2025, with credit monitoring offered.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_787231e8234473a9Vermont State AGfiled 2025-05-09Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/serviceaide-20250509.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 9, 2025
- Raw hash
- db1297889edf9c3dbef9b21cb78a58e4270da7e5edb849b26411bce2f17dd617
Reporting entity
- Name
- Serviceaide, Inc.norm: serviceaide
Victim entity
- Name
- Serviceaide, Inc.norm: serviceaide
Incident
- Discovered
- Nov 15, 2024
- Materiality determined
- —
- Notification sent
- May 9, 2025
- Affected individuals
- 32
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1074 Data Staged
- Regulator citations
- Notified the Office of the New Hampshire Attorney GeneralNotifying the U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 25 weeks(175 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.