DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDMediumContained

New Hampshire Hospital Association

bd_c7e5cd1200f0b999 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 20, 2025

Filed

Sep 22, 2025

To disclose

5 weeks

Affected

2state residents only

Linked

2 filings

Confidence

66%
Full breach record for New Hampshire Hospital Association

New Hampshire Hospital Association (NHHA) notified the NH Attorney General of a phishing incident on Sept 19, 2025. An employee's email was compromised on Aug 12, 2025, discovered Aug 20. Two NH residents' names and SSNs were potentially viewed. No evidence of data theft. NHHA contained the attack, notified residents Sept 18, provided 12 months credit monitoring, and enhanced security training.

Incident timeline

undetected · 8 days
discovery → filing · 5 weeks / 33 days

Aug 12, 2025

Begins

Aug 20, 2025

Discovered

Sep 22, 2025

Filed

vs. sector median

8 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Maine State AGSep 19 · first
New Hampshire State AG+3d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.