MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
TriValley Primary Care
bd_d568aa2fb9b57c25 · schema v1 · pii pii-v1
Full breach record for TriValley Primary Care →TriValley Primary Care notified the New Hampshire Attorney General of a ransomware incident discovered on October 11, 2021, affecting 11 NH residents. The breach exposed demographic, government ID (SSN), clinical, and financial data. The organization engaged forensic experts and the FBI, contained the threat, and provided credit monitoring to affected individuals. Notification was sent on November 24, 2021.
Leak gap clock⏱ Leak >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by groove about this victim predates this filing by 38 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a109c87c50e4d287Maine State AGfiled 2021-11-23(6d gap)Verified
- bd_db12c7445a73ebb6Montana State AGfiled 2021-11-23(6d gap)Candidate
- bd_c3d99a75329756c9Maine State AGfiled 2022-01-06(38d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/trivalley-primary-care-20211129.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 29, 2021
- Raw hash
- 2eff8501a369e676d1422de0d095899ab0a38ae7b1478bcac3f2b11672eebcdf
Reporting entity
- Name
- Whiteford, Taylor & Preston LLPnorm: whiteford taylor preston
- Domain
- whitefordlaw.com
Victim entity
- Name
- TriValley Primary Carenorm: trivalley primary care
- Domain
- trivalleypc.com
Incident
- Discovered
- Oct 11, 2021
- Materiality determined
- —
- Notification sent
- Nov 24, 2021
- Affected individuals
- 11
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Attorney General of New HampshireNotified applicable government regulators
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.