HackingCustomer Data InvolvedEmployee Data InvolvedData ExfiltratedPHIPIIIDENTITY_BASICMediumContained
A&A Services dba Sav-Rx
bd_815e884fb2c0f6c2 · schema v1 · pii pii-v1
Full breach record for A&A Services dba Sav-Rx →A&A Services d/b/a Sav-Rx experienced unauthorized access to its IT systems between October 3 and October 8, 2023. The incident compromised PHI and PII of 5,121 individuals, including 5,121 New Hampshire residents and 1,006 Rhode Island residents. The company engaged cybersecurity experts, restored systems, and provided credit monitoring. Notifications were sent in May 2024.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1333cc9cc2dc136dVermont State AGfiled 2024-05-24Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/a-a-services-sav-rx-20240524.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2024
- Raw hash
- 1eeb0db3effa5d51e1a1d861e2b14e55ed2d545daf03c37ba6a46d66e2dfde0a
Reporting entity
- Name
- A&A Services dba Sav-Rxnorm: a a services dba sav rx
Victim entity
- Name
- A&A Services dba Sav-Rxnorm: a a services dba sav rx
Incident
- Discovered
- Oct 8, 2023
- Materiality determined
- Apr 30, 2024
- Notification sent
- May 24, 2024
- Affected individuals
- 5,121
- Data types
- PHIPIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney GeneralNotified Secretary of Health and Human Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 33 weeks(229 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.