CorrectCare Integrated Health, Inc.
bd_c298f148370b91da · schema v1 · pii pii-v1
Full breach record for CorrectCare Integrated Health, Inc. →2 incidents on fileCorrectCare Integrated Health, LLC, a third-party health administrator, notified the New Hampshire Attorney General of a data security incident. On July 6, 2022, the company discovered that two file directories on a web server were inadvertently exposed to the public internet due to a misconfiguration. Investigation revealed patient information may have been accessible since January 22, 2022. The incident affected 391 New Hampshire residents, exposing PHI and PII. CorrectCare secured the server within nine hours, engaged forensic investigators, and offered 12 months of identity protection services. No misuse of information was detected.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 22, 2022
Begins
Jul 6, 2022
Discovered
May 22, 2023
Filed
vs. sector median
+33 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_4d14a7ac85bf85c12022-10-31 · +203dVerified
- HHS OCRbd_a793832c51c013362022-10-31 · +203dVerified
- HHS OCRbd_f3c7265441edcde02022-10-31 · +203dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Oct 31 (CA), last May 22 (NH) — a 203-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.