DisclosureLens
HackingHealthcareHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)Downstream VictimsPHIIdentity (basic)LowContained

Everside Health

bd_d02454a5de141ddd · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 27, 2023

Filed

Aug 17, 2023

To disclose

16 weeks

Affected

1state residents only

Linked

3 filings

Confidence

65%
Full breach record for Everside Health3 incidents on file

Everside Health, a healthcare provider and HIPAA Business Associate, notified the NH Attorney General of a security incident affecting one New Hampshire resident. Unauthorized access occurred between April 22-28, 2023, resulting in the copying of documents containing PHI. Suspicious activity was detected on April 27, 2023. Everside engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring to the affected individual.

Incident timeline

undetected · 5 days
discovery → filing · 16 weeks / 112 days

Apr 22, 2023

Begins

Apr 27, 2023

Discovered

Apr 29, 2023

Scope determined

Aug 17, 2023

Filed

vs. sector median

+3 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Massachusetts State AGAug 17 · first
New Hampshire State AGAug 17 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.