HackingCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICHEALTH_BASICPHILowContained
OnePoint Patient Care
bd_b99dbbb3e344646d · schema v1 · pii pii-v1
Full breach record for OnePoint Patient Care →OnePoint Patient Care reported a data security incident to the New Hampshire Attorney General. On August 8, 2024, OPPC detected suspicious activity and determined an unauthorized third party accessed its network between August 3-8, 2024. The incident affected 843 New Hampshire residents, exposing personal information including names, addresses, medical record numbers, diagnoses, and prescription data. OPPC engaged forensic experts, notified law enforcement, and offered one year of credit monitoring.
Leak gap clock⏱ Leak >90d16 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
A leak claim by inc_ransom about this victim predates this filing by 111 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e783d73da1f1cb11Maine State AGfiled 2024-11-22(3d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/onepoint-patient-care-20241125.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 25, 2024
- Raw hash
- ed8410395990038effa486a482ea0ebc0183e3ad6c1024ea256a63b900f5a7b3
Reporting entity
- Name
- OnePoint Patient Carenorm: onepoint patient care
Victim entity
- Name
- OnePoint Patient Carenorm: onepoint patient care
Incident
- Discovered
- Aug 8, 2024
- Materiality determined
- Sep 27, 2024
- Notification sent
- Oct 21, 2024
- Affected individuals
- 843
- Data types
- PIIIDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(109 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.