Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIPHIIDENTITY_BASICMediumContained
The Mount Kisco Surgery Center LLC
bd_9a8fe933940dea3e · schema v1 · pii pii-v1
Full breach record for The Mount Kisco Surgery Center LLC →The Mount Kisco Surgery Center LLC (dba ASCW) notified the NH AG of a data security incident. On Nov 3, 2023, unusual activity was discovered in an employee's email account. Unauthorized access occurred between Oct 23 and Nov 3, 2023. The incident involved phishing leading to credential compromise and email collection. Personal and PHI of 21,073 individuals were potentially affected, including 19 NH residents. ASCW engaged forensic investigators, secured the account, and offered identity protection services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8af3e03d49b06830Vermont State AGfiled 2024-06-26Candidate
- bd_98faef4f7fe7242fIndiana State AGfiled 2024-06-26Verified
- bd_d25e9f8730294417HHS OCRfiled 2024-06-25(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mount-kisco-surgery-center-ambulatory-surgery-center-westchester-20240626.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2024
- Raw hash
- ac6f8bb02ab8320167ac3a2dfd824859eccc78d4d612308138115f1750762bc6
Reporting entity
- Name
- The Mount Kisco Surgery Center LLCnorm: the mount kisco surgery center
Victim entity
- Name
- The Mount Kisco Surgery Center LLCnorm: the mount kisco surgery center
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- May 30, 2024
- Notification sent
- Jun 26, 2024
- Affected individuals
- 21,073
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella, Consumer Protection Bureau, Office of the Attorney General, NH
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(236 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.