Health Care and Rehabilitation Services of Southeastern Vermont, Inc.
bd_ad2c7c9aae377c3f · schema v1 · pii pii-v1
Full breach record for Health Care and Rehabilitation Services of Southeastern Vermont, Inc. →Health Care and Rehabilitation Services of Southeastern Vermont, Inc. (HCRS) submitted a supplemental notification to the New Hampshire Attorney General regarding unauthorized access to two email accounts. The incident involved phishing leading to credential compromise, with unauthorized access occurring between December 4 and December 9, 2024. HCRS discovered the breach on December 20, 2024. Personal information of 70 New Hampshire residents, including names, SSNs, and driver's license numbers, was accessed. HCRS reset passwords, engaged forensic investigators, and offered credit monitoring to affected individuals.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_70a94fe33c8d5781Vermont State AGfiled 2025-07-31(4d gap)Candidate
- bd_aa10c82806c65eebNew Hampshire State AGfiled 2025-06-23(42d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/health-care-rehabilitation-services-southeastern-vermont-20250804.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2025
- Raw hash
- 3084cb259b68a36828adab26da83f3bb470885e25c557b7e325d2d2b43de4454
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Health Care and Rehabilitation Services of Southeastern Vermont, Inc.norm: health care and rehabilitation services of southeastern vermont
Incident
- Discovered
- Dec 20, 2024
- Materiality determined
- —
- Notification sent
- Jun 18, 2025
- Affected individuals
- 70
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided supplemental notification to New Hampshire Attorney General's Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 32 weeks(227 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.