Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Catholic Health Services
bd_b530e7b31b78e48f · schema v1 · pii pii-v1
Full breach record for Catholic Health Services →Catholic Hospice notified the New Hampshire Attorney General on January 14, 2022, regarding a data security incident involving the compromise of three employee email accounts. The breach impacted four New Hampshire residents, exposing names, Social Security numbers, and protected health information (PHI). Catholic Hospice engaged forensic experts, reset passwords, and provided credit monitoring services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/catholic-hospice-20220114.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2022
- Raw hash
- 8cd8f636aff9a7e30ed21cec632ea291a955175159d182eeccaec91758b72dec
Reporting entity
- Name
- Catholic Health Servicesnorm: catholic health
- Domain
- catholichealthservices.org
Victim entity
- Name
- Catholic Health Servicesnorm: catholic health
- Domain
- catholichealthservices.org
Incident
- Discovered
- Dec 1, 2021
- Materiality determined
- —
- Notification sent
- Jan 14, 2022
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notice has also been provided to the Department of Health and Human Services, Office of Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.