HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Southwest Behavioral Health Center
bd_bf02f75cafda850d · schema v1 · pii pii-v1
Full breach record for Southwest Behavioral Health Center →Southwest Behavioral Health Center (SBHC) notified the New Hampshire Attorney General on November 20, 2023, of a cybersecurity incident discovered on March 13, 2023. The breach affected 3 New Hampshire residents, potentially exposing personal information. SBHC engaged forensic investigators, notified the FBI, and sent notification letters offering credit monitoring and identity theft protection services.
Leak gap clock✗ Leak >180d36 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 214 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_57a9c019676a5d10Montana State AGfiled 2023-11-20Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/southwest-behavioral-health-center-20231120.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2023
- Raw hash
- 565938ee2f1bdb0baedad4ad85a6c56533b8e56419c4166af58010e92e4af76c
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Southwest Behavioral Health Centernorm: southwest behavioral health center
- Domain
- sbhc.us
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- Nov 9, 2023
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 36 weeks(252 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.