HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICLowContained
Baptist Health
bd_a61e9229c54784d5 · schema v1 · pii pii-v1
Full breach record for Baptist Health →Baptist Health notified the NH Attorney General of a security incident at Baptist Health Medical Center-Drew County. Unauthorized access occurred between April 22 and July 8, 2024, affecting employee and dependent PII. Baptist Health became aware on July 8, 2024, engaged forensic investigators, notified law enforcement, and mailed notifications to 1 NH resident on Sept 30, 2024, offering Experian IdentityWorks.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a995de4be49aa312Indiana State AGfiled 2024-09-30(2d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/baptist-health-20241002.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 2, 2024
- Raw hash
- 5aa7e1451e7614cea17ad482f20c72209b4750d851f12589d09cd50bed3b41f7
Reporting entity
- Name
- Baptist Healthnorm: baptist health
Victim entity
- Name
- Baptist Healthnorm: baptist health
Incident
- Discovered
- Jul 8, 2024
- Materiality determined
- Sep 17, 2024
- Notification sent
- Sep 30, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.