HackingStolen CredentialsCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Postmeds, Inc.
bd_cc30f060acac4baf · schema v1 · pii pii-v1
Full breach record for Postmeds, Inc. →Postmeds, Inc. notified the New Hampshire Attorney General of a security incident affecting one NH resident. Unauthorized access occurred between Aug 30 and Sep 1, 2023, discovered Aug 31, 2023. The breach involved pharmacy management files containing PHI and demographic data. Postmeds engaged cybersecurity professionals, secured the environment, and offered credit monitoring to the affected individual.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_082b80ffa053fb24Vermont State AGfiled 2024-01-17(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/postmeds-20240118.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 18, 2024
- Raw hash
- d7d9e88dd67cb68cafad0e0e2371a499a0a55d3cac0a9815a89adf75b1114b0f
Reporting entity
- Name
- Postmeds, Inc.norm: postmeds
Victim entity
- Name
- Postmeds, Inc.norm: postmeds
Incident
- Discovered
- Aug 31, 2023
- Materiality determined
- Dec 21, 2023
- Notification sent
- Jan 17, 2024
- Affected individuals
- 1
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(140 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.