HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Riverside Medical Gr
bd_c3f0dcc5e30e8f56 · schema v1 · pii pii-v1
Full breach record for Riverside Medical Gr →Riverside Medical Group (part of Optum) notified the New Hampshire Attorney General on September 27, 2022, of a data breach affecting 7 NH residents. On August 3, 2022, an independent legacy server containing patient immunization records and PII (including SSNs for 1 resident) was compromised. The server was locked down, and notifications were sent on September 30, 2022. No actual misuse was identified.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4618ae56dcbd7aefMontana State AGfiled 2022-09-27Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/riverside-medical-group-20220927.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 27, 2022
- Raw hash
- 9204406c301b296fd755b0fa1a4d5171ab8d5eae3a43790620b71bbbc766a09a
Reporting entity
- Name
- Riverside Medical Grnorm: riverside medical gr
- Domain
- riversidemed.com
Victim entity
- Name
- Riverside Medical Grnorm: riverside medical gr
- Domain
- riversidemed.com
Incident
- Discovered
- Aug 3, 2022
- Materiality determined
- —
- Notification sent
- Sep 30, 2022
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.