HackingStolen CredentialsCustomer Data InvolvedTargetedPIIIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
GATEWAY REHABILITATION CENTER
bd_9fb984e36d34b4a7 · schema v1 · pii pii-v1
Full breach record for GATEWAY REHABILITATION CENTER →Gateway Rehabilitation Center, a non-profit drug and alcohol rehabilitation provider, disclosed a data security incident discovered on June 13, 2022. The incident involved unauthorized access to systems, potentially compromising patient names and Social Security numbers. Eight New Hampshire residents were notified. The company engaged forensic experts, reported the incident to the FBI, and provided complimentary credit monitoring and identity protection services to affected individuals.
Leak gap clock⏱ Leak >90d23 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by blackbyte about this victim predates this filing by 135 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_f6493c4126c29b05Leak Siteblackbytefiled 2022-07-06(135d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_05ee2fe15ab13820HHS OCRfiled 2022-11-18Candidate
- bd_b6bd6c502fbaca93Maine State AGfiled 2022-11-18Verified by operator
- bd_e1861cbb398ac64dMontana State AGfiled 2022-11-17(1d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gateway-rehabilitation-center-20221118.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2022
- Raw hash
- ee1587fedd31276bc998008418eac02c46f819ae143506c1f97b3e6ef85b2807
Reporting entity
- Name
- GATEWAY REHABILITATION CENTERnorm: gateway rehabilitation center
Victim entity
- Name
- GATEWAY REHABILITATION CENTERnorm: gateway rehabilitation center
Incident
- Discovered
- Jun 13, 2022
- Materiality determined
- Jul 8, 2022
- Notification sent
- Nov 18, 2022
- Affected individuals
- 8
- Data types
- PIIIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney GeneralReported incident to the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(158 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.