HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Anatomic Clinical Laboratory Associates
bd_a662f10ccf915a7c · schema v1 · pii pii-v1
Full breach record for Anatomic Clinical Laboratory Associates →Anatomic and Clinical Laboratory Associates, P.C. (ACLA) notified the New Hampshire Attorney General on June 23, 2026, of a data event affecting 21 NH residents. Discovered Dec 1, 2025, an unknown actor gained unauthorized access and downloaded files containing names, SSNs, and PHI. ACLA engaged external experts, secured the network, notified regulators and credit bureaus, and offered 12 months of credit monitoring via Epiq.
Leak gap clock✗ Leak >180d29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by insomnia about this victim predates this filing by 210 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_44af52239b6ffd31Massachusetts State AGfiled 2026-06-01(22d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/anatomic-clinical-laboratory-associates-20260623.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2026
- Raw hash
- 302be42448cfadab65481ac24102d501176b25143e8b17911d1f568c62ee695f
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Anatomic Clinical Laboratory Associatesnorm: anatomic clinical laboratory associates
- Domain
- aclapath.com
- Industry
- healthcare
Incident
- Discovered
- Dec 1, 2025
- Materiality determined
- —
- Notification sent
- Jun 23, 2026
- Affected individuals
- 21
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- providing written notice of this incident to relevant regulators, law enforcement and to the three major credit reporting agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 weeks(204 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.