HackingStolen CredentialsData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedSupply Chain (3P Vendor)PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NORTHWELL HEALTH, INC.
bd_781a6b647e1d2e28 · schema v1 · pii pii-v1
Full breach record for NORTHWELL HEALTH, INC. →Perry Johnson & Associates (PJ&A), a medical transcription vendor, reported a data breach affecting Northwell Health, Crouse Health, and CarePoint Health. Unauthorized access occurred March 27–May 2, 2023, via compromised RDS credentials. The actor demanded ransom and exfiltrated PHI and PII. 867 New Hampshire residents were notified on November 3, 2023, with credit monitoring offered. PJ&A engaged forensic investigators and law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed867 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/perry-johnson-associates-aka-pja-20231103.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2023
- Raw hash
- c5007ad07e23bd235b20a491d54ff32435cf861bc00ea55fc2c6e55ad426eee3
Reporting entity
- Name
- Perry Johnson & Associatesnorm: perry johnson associates
Victim entity
- Name
- NORTHWELL HEALTH, INC.norm: northwell health
Incident
- Discovered
- May 2, 2023
- Materiality determined
- —
- Notification sent
- Nov 3, 2023
- Affected individuals
- 867
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(185 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.