AccidentalMisdeliveryCustomer Data InvolvedPHIIDENTITY_BASICLowResolved
Midi Health, Inc.
bd_de8fab03d9f1cf06 · schema v1 · pii pii-v1
Full breach record for Midi Health, Inc. →Midi Health, Inc. notified the NH Attorney General of an error where refund checks mailed to patients in Feb/Mar 2025 included an invoice with PHI and PII of approximately 18 other patients. One NH resident was affected. Discovery was March 3, 2025; notification sent March 14, 2025. Incident resolved.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed18 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/midi-health-20250319.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2025
- Raw hash
- eba68bd6b0ad5feffdf241adcf44f2ebe71d48dfa19dba44a004c68eb18bfa2c
Reporting entity
- Name
- Midi Health, Inc.norm: midi health
Victim entity
- Name
- Midi Health, Inc.norm: midi health
Incident
- Discovered
- Mar 3, 2025
- Materiality determined
- —
- Notification sent
- Mar 14, 2025
- Affected individuals
- 18
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1535 Untrusted Webmail Service
- Regulator citations
- Providing notification to federal and state government agencies
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.