DisclosureLens
HackingHealthcareHealthcareCustomer Data InvolvedDelayed DiscoveryPHIHealth (basic)Identity (basic)LowContained

Averhealth Holdings

bd_9df113154ca2a6b7 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jan 20, 2026

Filed

Jul 20, 2026

To disclose

26 weeks

Affected

12state residents only

Linked

4 filings

Confidence

67%
Full breach record for Averhealth Holdings

Averhealth Holdings detected unusual activity in its email environment on January 20, 2026. An investigation concluded on May 6, 2026, that personal information of 12 New Hampshire residents may have been accessed. Affected data included names, dates of birth, diagnoses, health insurance policy numbers, medical costs, dates of service, provider names, medical record numbers, and treatment information. Social Security numbers were not affected. The company secured the email environment, engaged cybersecurity professionals, and offered one year of credit monitoring.

Incident timeline

discovery → filing · 26 weeks / 181 days

Jan 20, 2026

Discovered

Jul 20, 2026

Filed

vs. sector median

+13 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
HHS OCRJul 2 · first
New Hampshire State AG+18d · this page

Pattern: first filing Jul 2 (VA), last Jul 20 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.