HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Kentucky Mountain Health Alliance, Inc.
bd_7659d88af43fd86f · schema v1 · pii pii-v1
Full breach record for Kentucky Mountain Health Alliance, Inc. →Kentucky Mountain Health Alliance, Inc. (KMHA) notified the New Hampshire Attorney General of a data event affecting one NH resident. Unauthorized access occurred on or around September 16, 2025, involving the viewing and obtaining of files containing SSNs, driver's licenses, passport numbers, financial account info, and PHI. KMHA took systems offline, engaged a cybersecurity firm, and reported to law enforcement. Notification was sent to the affected resident on June 12, 2026, offering one year of identity monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a107d4aed7ab0f65Indiana State AGfiled 2026-06-12(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kentucky-mountain-health-alliance-20260619.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 19, 2026
- Raw hash
- 4d180bafbd2f15b71453628b844481c9e67b6268f1ea1b9b3212a0ab3e806587
Reporting entity
- Name
- SMITH GAMBRELL & RUSSELL LLPnorm: smith gambrell russell
- Domain
- sgrlaw.com
Victim entity
- Name
- Kentucky Mountain Health Alliance, Inc.norm: kentucky mountain health alliance
- Domain
- kymha.com
Incident
- Discovered
- Sep 16, 2025
- Materiality determined
- —
- Notification sent
- Jun 12, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 39 weeks(276 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.