HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)Downstream VictimsPHIIDENTITY_BASICLowContained
Everside Health
bd_d02454a5de141ddd · schema v1 · pii pii-v1
Full breach record for Everside Health →Everside Health, a healthcare provider and HIPAA Business Associate, notified the NH Attorney General of a security incident affecting one New Hampshire resident. Unauthorized access occurred between April 22-28, 2023, resulting in the copying of documents containing PHI. Suspicious activity was detected on April 27, 2023. Everside engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring to the affected individual.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/everside-health-20230817.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2023
- Raw hash
- b0d8ccc80fe4d1e1171730a0aefa30d21482aff61a26aa6531b18f3edc4fd050
Reporting entity
- Name
- Everside Healthnorm: everside health
Victim entity
- Name
- Everside Healthnorm: everside health
Incident
- Discovered
- Apr 27, 2023
- Materiality determined
- Apr 29, 2023
- Notification sent
- Aug 17, 2023
- Affected individuals
- 1
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.