HackingPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Avamere Health Services, LLC
bd_dbfc6c9f626ea5b4 · schema v1 · pii pii-v1
Full breach record for Avamere Health Services, LLC →Avamere Health Services, LLC reported a cybersecurity incident to the New Hampshire Attorney General on July 16, 2022. The breach involved intermittent unauthorized access to a third-party hosted network between January 19, 2022, and March 17, 2022. The incident compromised protected health information (PHI) and personally identifiable information (PII) of individuals. Avamere engaged forensic investigators and law enforcement, and sent notifications to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a59ac3e65c757f3bLeak Siteavoslockerfiled 2022-12-26(163d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_d6171759266d62f8HHS OCRfiled 2022-07-13(3d gap)Verified
- bd_8f3805fe6b98937aMaine State AGfiled 2022-07-06(10d gap)Verified by operator
- bd_3bf1b9ebbb2c181eOregon State AGfiled 2022-06-30(16d gap)Verified by operator
- bd_6b1622e1e53f83e8Washington State AGfiled 2022-06-27(19d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 29d gap
- bd_6efd83b0279b1fe4Montana State AGfiled 2022-06-17(29d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/avamere-health-services-20220716.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 16, 2022
- Raw hash
- 4a32881b40b678829cbf84816c990f327e97b30fc66942831b575c462183971a
Reporting entity
- Name
- Avamere Health Services, LLCnorm: avamere health
Victim entity
- Name
- Avamere Health Services, LLCnorm: avamere health
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 16, 2022
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.