MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIMediumContained
Lamoille Health Partners
bd_73720fe4f4c0f848 · schema v1 · pii pii-v1
Full breach record for Lamoille Health Partners →Lamoille Health Partners reported a supplemental ransomware incident to New Hampshire AG. Unauthorized access occurred June 12-13, 2022, resulting in file encryption and potential data exfiltration. 431 NH residents affected. Data included names, SSNs, driver's licenses, financial accounts, and PHI. Discovery was June 13, 2022. Remediation included forensic investigation, law enforcement notification, and credit monitoring services.
Leak gap clock⏱ Leak >90d27 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed431 affectedView incident
A leak claim by blackbyte about this victim predates this filing by 169 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lamoille-health-partners-20221222.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2022
- Raw hash
- 0b0c848026818f596850fb673402b78d29a08fddef74bf280dcc9159d2efe359
Reporting entity
- Name
- Lamoille Health Partnersnorm: lamoille health
Victim entity
- Name
- Lamoille Health Partnersnorm: lamoille health
Incident
- Discovered
- Jun 13, 2022
- Materiality determined
- Oct 26, 2022
- Notification sent
- Dec 22, 2022
- Affected individuals
- 431
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the Attorney General of the State of New Hampshire
Compliance
- Time to disclose
- 27 weeks(192 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.