MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Atlantic General Hospital Corporation
bd_be16c1876a6e4ee6 · schema v1 · pii pii-v1
Full breach record for Atlantic General Hospital Corporation →Atlantic General Hospital notified the New Hampshire Attorney General on March 24, 2023, of a ransomware incident discovered on January 29, 2023. Unauthorized access to servers began on January 20, 2023. The breach affected 15 New Hampshire residents, exposing names and Social Security numbers. AGH engaged forensic specialists, notified law enforcement and HHS, and provided 12 months of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_59e7e34a942ade82Montana State AGfiled 2023-03-24(3d gap)Candidate
- bd_c4598d4c0bd61c34Maine State AGfiled 2023-03-24(3d gap)Candidate
- bd_d38bbaf5ade2752cDelaware State AGfiled 2023-03-24(3d gap)Verified
- bd_42de4d871ce9fac9Vermont State AGfiled 2023-06-22(87d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 88d gap
- bd_77bb476d0371ff91Delaware State AGfiled 2023-06-22(87d gap)Verified
- bd_ae2055f751dbc9b3Maine State AGfiled 2023-06-23(88d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/atlantic-general-hospital-20230327.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2023
- Raw hash
- 38e94a69fb36f3327849fbce8ed29be3666ac1b91f24b0ed997b5720b1ce3033
Reporting entity
- Name
- Atlantic General Hospital Corporationnorm: atlantic general hospital
Victim entity
- Name
- Atlantic General Hospital Corporationnorm: atlantic general hospital
Incident
- Discovered
- Jan 29, 2023
- Materiality determined
- Mar 6, 2023
- Notification sent
- Mar 24, 2023
- Affected individuals
- 15
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementProvided written notice to relevant state regulatorsNotified the U.S. Department of Health and Human Services pursuant to HIPAA
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.