DisclosureLens
Social EngineeringHealthcareProfessional ServicesHealthcarePhishingCustomer Data InvolvedTargetedIdentity (basic)Government IDHealth (basic)PHIMediumContained

North America Administrators, L.P.

bd_b9e3f4f73f6498c2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 30, 2018

Filed

May 11, 2018

To disclose

6 weeks

Affected

2state residents only

Confidence

66%
Full breach record for North America Administrators, L.P.

North America Administrators, LP (NAA) notified the NH Attorney General of a phishing incident affecting 2 NH residents. Unauthorized access to employee email accounts occurred Jan 7-24, 2018. NAA discovered the incident on March 30, 2018, and notified affected members on May 11, 2018. Data exposed included names, SSNs, and medical info. NAA engaged forensic investigators, implemented MFA, and provided credit monitoring.

Incident timeline

undetected · 82 days
discovery → filing · 6 weeks / 42 days

Jan 7, 2018

Begins

Mar 30, 2018

Discovered

May 11, 2018

Filed

vs. sector median

7 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.