Sunspire Health
bd_8bbe907ad88eec4d · schema v1 · pii pii-v1
Full breach record for Sunspire Health →Sunspire Health, a network of addiction treatment facilities, notified New Hampshire residents of a phishing campaign that compromised employee email credentials between March 1 and May 4, 2018. The incident affected 74 NH residents, exposing PHI, SSNs, and financial data. Sunspire engaged forensic investigators, reset credentials, and provided 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 1, 2018
Begins
Apr 10, 2018
Discovered
Jul 30, 2018
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Oregon State AGbd_6b6d76f70c52ed832018-07-27 · +3dVerified
- Montana State AGbd_cfcc4c084e3106342018-07-27 · +3dVerified
- HHS OCRbd_8130adbe758812e02018-07-16 · +14dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jul 16 (NJ), last Jul 30 (NH) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.