Carestream Health, Inc.
bd_df5674eef386dc04 · schema v1 · pii pii-v1
Full breach record for Carestream Health, Inc. →Carestream Health, Inc. notified the NH Attorney General of a cyberattack on May 1, 2020, where unauthorized parties accessed internal IT systems and acquired files containing names, SSNs, addresses, and direct deposit bank account information for 5 New Hampshire residents. The company blocked access, engaged forensic experts and the FBI, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 1, 2020
Begins
May 1, 2020
Discovered
May 11, 2020
Filed
vs. sector median
11 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Oregon State AGbd_360108de854b6d562020-05-08 · +3dCandidate
- Montana State AGbd_38d853a2fa1e2a192020-05-08 · +3dVerified
- Indiana State AGbd_46ef840d4e126a472020-05-08 · +3dVerified
- Massachusetts State AGbd_d3669cb1d96d5d662020-05-08 · +3dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.