HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Health Care and Rehabilitation Services of Southeastern Vermont, Inc.
bd_aa10c82806c65eeb · schema v1 · pii pii-v1
Full breach record for Health Care and Rehabilitation Services of Southeastern Vermont, Inc. →Health Care and Rehabilitation Services of Southeastern Vermont, Inc. (HCRS) reported unauthorized access to two email accounts between Dec 4-9, 2024. HCRS detected the incident on Dec 20, 2024. The breach exposed NH residents' PII including SSNs, driver's licenses, medical history, and health insurance info. HCRS engaged forensic investigators, reset passwords, and offered 12 months of credit monitoring to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_70a94fe33c8d5781Vermont State AGfiled 2025-07-31(38d gap)Candidate
- bd_ad2c7c9aae377c3fNew Hampshire State AGfiled 2025-08-04(42d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/health-care-rehabilitation-services-southeastern-vermont-20250623.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2025
- Raw hash
- 910256acc64b8cebbfdaca5aa094603bb2410f570add2e5389e8f89114813eec
Reporting entity
- Name
- Health Care and Rehabilitation Services of Southeastern Vermont, Inc.norm: health care and rehabilitation services of southeastern vermont
Victim entity
- Name
- Health Care and Rehabilitation Services of Southeastern Vermont, Inc.norm: health care and rehabilitation services of southeastern vermont
Incident
- Discovered
- Dec 20, 2024
- Materiality determined
- May 13, 2025
- Notification sent
- Jun 18, 2025
- Affected individuals
- 20
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(185 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.