HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
The Center for Advanced Eye Care
bd_d23e6ecf72cd6312 · schema v1 · pii pii-v1
Full breach record for The Center for Advanced Eye Care →Center for Advanced Eye notified NH AG of a cybersecurity incident discovered on Dec 16, 2025, involving unauthorized access to an Amazon S3 bucket containing legacy EHR data. One NH resident was affected. Compromised data included names, DOB, SSN, medical record numbers, and health info. The Practice isolated the environment, engaged forensic investigators, and offered 12 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/center-advanced-eye-20260612.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2026
- Raw hash
- 11e42ec29761e1bb15629d54caf05db370aa7214c06c320ea8e61b4a331c4fe2
Reporting entity
- Name
- The Center for Advanced Eye Carenorm: the center for advanced eye care
Victim entity
- Name
- The Center for Advanced Eye Carenorm: the center for advanced eye care
Incident
- Discovered
- Dec 16, 2025
- Materiality determined
- —
- Notification sent
- Jun 12, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(178 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.