HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Colorado Health Network Inc
bd_e976b45e273a745f · schema v1 · pii pii-v1
Full breach record for Colorado Health Network Inc →Colorado Health Network Inc. notified the New Hampshire Attorney General of a data event occurring on or around July 29, 2025. An unauthorized individual accessed the network, viewing files containing PHI and PII (SSN, driver's license, financial data). Three New Hampshire residents were identified and notified on June 18, 2026. The company engaged a cybersecurity firm, took systems offline, and offered identity monitoring.
Leak gap clock✗ Leak >180d47 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by cephalus about this victim predates this filing by 297 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b783935888d40154Vermont State AGfiled 2026-06-22Verified
- bd_c5c99f68257da486Texas State AGfiled 2026-06-25(3d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/colorado-health-network-20260622.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 22, 2026
- Raw hash
- 4b01b17ecb5a03e9df0236e2bf0d225c39cb7f308438d39c8643211ffe8ff526
Reporting entity
- Name
- Colorado Health Network Incnorm: colorado health network
- Domain
- coloradohealthnetwork.org
Victim entity
- Name
- Colorado Health Network Incnorm: colorado health network
- Domain
- coloradohealthnetwork.org
Incident
- Discovered
- Jul 29, 2025
- Materiality determined
- —
- Notification sent
- Jun 18, 2026
- Affected individuals
- 3
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 47 weeks(328 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.