Legacy Treatment Services
bd_c53e05a41e7e0934 · schema v1 · pii pii-v1
Full breach record for Legacy Treatment Services →2 incidents on fileLegacy Treatment Services, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 3 NH residents. Unauthorized access occurred between Oct 6-11, 2024. Data included names, SSNs, and health info. Legacy engaged forensic investigators, took systems offline, and notified law enforcement. Notifications to residents began Aug 22, 2025, offering credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 6, 2024
Begins
Jul 18, 2025
Discovered
Aug 25, 2025
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_1b6f00452a58973e2025-08-22 · +3dVerified by operator
- Vermont State AGbd_2163f16572f12a4f2025-08-22 · +3dVerified by operator
- Maine State AGbd_eb554231f98f22042025-08-22 · +3dVerified by operator
- HHS OCRbd_5a4c54d35d7bfc7e2024-12-31 · +237dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Dec 31 (NJ), last Aug 25 (NH) — a 237-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.