MalwareRansomwareRansom DemandedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Summit Surgical
bd_834bd4e90ea8e6ce · schema v1 · pii pii-v1
Full breach record for Summit Surgical →Summit Surgical, LLC, a Kansas-based physician-owned specialty hospital, notified the New Hampshire Attorney General of a cybersecurity attack detected on October 8, 2021. The incident involved a ransomware attempt by an unauthorized third party. One New Hampshire resident was potentially affected, with exposure of names, addresses, SSNs, and protected health information. Summit Surgical engaged forensic investigators, worked with law enforcement, and offered 12 months of credit monitoring and identity theft protection.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_bf0f9dadd30ee782Montana State AGfiled 2022-03-28(2d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/summit-surgical-20220330.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2022
- Raw hash
- d1d3ecec1ff188ddb616f278cb0216e3fa39e031e319ad157214bb16b9d754d5
Reporting entity
- Name
- Summit Surgicalnorm: summit surgical
- Domain
- summitsurgicals.com
Victim entity
- Name
- Summit Surgicalnorm: summit surgical
- Domain
- summitsurgicals.com
Incident
- Discovered
- Oct 8, 2021
- Materiality determined
- —
- Notification sent
- Mar 28, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(173 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.