HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTAUTHENTICATIONBIOMETRICHEALTH_BASICPHIMediumContained
SimonMed Imaging
bd_de5ba496eb09b6ca · schema v1 · pii pii-v1
Full breach record for SimonMed Imaging →SimonMed Imaging notified the New Hampshire AG of a data incident involving a third-party vendor. Unauthorized access occurred Jan 21–Feb 5, 2025. The breach affected 73 NH residents, exposing PHI, SSNs, driver's licenses, financial accounts, and authentication credentials. SimonMed engaged forensic professionals, reset passwords, enhanced MFA, and notified law enforcement.
Leak gap clock✗ Leak >180d37 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 260 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_835598e1f113f738Texas State AGfiled 2025-10-14Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/simonmed-imaging-20251014.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 14, 2025
- Raw hash
- d83205366906706cb6ff73197fae5ccac3d8d6e703dab50cbf1f0d031a2ac82d
Reporting entity
- Name
- Octillo Law Firmnorm: octillo law firm
- Domain
- octillolaw.com
Victim entity
- Name
- SimonMed Imagingnorm: simonmed imaging
- Domain
- simonmed.com
Incident
- Discovered
- Jan 28, 2025
- Materiality determined
- —
- Notification sent
- Oct 10, 2025
- Affected individuals
- 73
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTAUTHENTICATIONBIOMETRICHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this Incident to relevant government agencies
- Initial access
- supply_chain
Compliance
- Time to disclose
- 37 weeks(259 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.