Heart South Cardiovascular Group
bd_718fd6945d5f1904 · schema v1 · pii pii-v1
Full breach record for Heart South Cardiovascular Group →4 incidents on fileHeart South Cardiovascular Group notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 2 NH residents. On November 11, 2025, the group learned an unauthorized party claimed to possess data. Investigation found no unauthorized network access, but a bad actor posted limited data on the dark web. Patient PII (names, SSNs, DOB) and PHI (treatments, diagnoses) were potentially exposed. Notifications began April 6, 2026, offering credit monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 11, 2025
Discovered
Apr 13, 2026
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siterhysidabd_2028c3f5990168862025-11-10 · +153dVerified by operator
Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_75ff5c082c82aced2026-04-06 · +7dVerified
- Nebraska State AGbd_c12dc0d5f533ec4e2026-04-06 · +7dVerified by operator
- Maine State AGbd_dc4e83aef803c8912026-04-06 · +7dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Apr 6 (AL), last Apr 13 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.