DisclosureLens
HackingHealthcareHealthcareStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Evoke Wellness at Cohasset (?MCAT?)

bd_c882133aca817963 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 7, 2025

Filed

Feb 20, 2026

To disclose

28 weeks

Affected

7state residents only

Linked

3 filings

Confidence

67%
Full breach record for Evoke Wellness at Cohasset (?MCAT?)

Evoke Wellness at Cohasset, a medical health provider, notified the New Hampshire Attorney General of a data incident discovered on August 7, 2025. Unauthorized access potentially compromised patient information including names, addresses, SSNs, driver's licenses, and credit card data. Seven New Hampshire residents were identified and notified via mail on February 20, 2026. The organization offered 12 months of credit monitoring through Cyberscout/TransUnion and implemented additional security measures.

Incident timeline

discovery → filing · 28 weeks / 197 days

Aug 7, 2025

Discovered

Feb 20, 2026

Filed

vs. sector median

+16 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Indiana State AGFeb 20 · first
Massachusetts State AGFeb 20 · first
New Hampshire State AGFeb 20 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.