St. Mary's Health
bd_b5221e5123248fee · schema v1 · pii pii-v1
Full breach record for St. Mary's Health →3 incidents on fileSt. Mary's Health, Inc. d/b/a St. Vincent Evansville notified the NH Attorney General of a data incident affecting 4 New Hampshire residents. On February 12, 2018, the hospital detected unusual internet traffic accessing a server hosting credentialing software. Investigation revealed a server configuration error that exposed data to the internet. The server was taken offline and reconfigured. Forensic analysis indicated unauthorized access attempts from outside the US, but no evidence of data posting to the dark web was found. Affected data included names, addresses, dates of birth, phone numbers, driver's licenses, SSNs, and National Provider Data Bank reports. The hospital offered one year of identity theft monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 12, 2018
Discovered
May 31, 2018
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Montana State AGbd_6b42da67f36d5a2c2018-05-31Candidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.