Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICLowContained
Access TeleCare
bd_a685c2b56520cb69 · schema v1 · pii pii-v1
Full breach record for Access TeleCare →Access TeleCare notified New Hampshire AG of a data event affecting 55 residents. Suspicious activity on an employee email account was discovered on Jan 8, 2024. Unauthorized access occurred between Nov 6, 2023 and Jan 8, 2024. Personal information was potentially accessed. Access TeleCare disabled the account, engaged forensic specialists, and provided credit monitoring services.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_68966e9e1dda38fbCalifornia State AGfiled 2024-12-23Candidate
- bd_7386e5a0fcb6fa66Vermont State AGfiled 2024-12-23Verified
- bd_89d95e54e9a9677aCalifornia State AGfiled 2025-03-14(81d gap)Verified
- bd_98e39108670c7a63Vermont State AGfiled 2025-03-14(81d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/access-telecare-20241223.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2024
- Raw hash
- ce057fdb3f7615b8f6376d594bb3032305cc2ad43e24f6b6a547f5768bc35907
Reporting entity
- Name
- Access TeleCarenorm: access telecare
Victim entity
- Name
- Access TeleCarenorm: access telecare
Incident
- Discovered
- Jan 8, 2024
- Materiality determined
- Aug 30, 2024
- Notification sent
- Dec 23, 2024
- Affected individuals
- 55
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human ServicesNotified prominent media pursuant to HIPAAProvided written notice to relevant state and federal regulatorsNotified the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- phishing_link
Compliance
- Time to disclose
- 50 weeks(350 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.