MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Keys Pathology Associates, PA
bd_ebbf1e0abb1d9464 · schema v1 · pii pii-v1
Full breach record for Keys Pathology Associates, PA →Keys Pathology Associates, PA notified the New Hampshire Attorney General of a data event involving 26 state residents. A third-party billing vendor, Genesis Billing Services, was hacked on or about May 20, 2025. The threat actor exfiltrated and encrypted files containing patient PII and PHI. Keys Pathology terminated its contract with Genesis and is offering credit monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8503d1aecfd6ec08Vermont State AGfiled 2025-09-04Verified
- bd_8f41d737524aaabcIndiana State AGfiled 2025-09-05(1d gap)Verified
- bd_837ebe4439f908adMaine State AGfiled 2025-09-02(2d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/keys-pathology-20250904.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2025
- Raw hash
- 6e0066cfc15cb909542fd23aa2110dfef096f9c240060eed4a0b8b6043bfb5a3
Reporting entity
- Name
- Spencer Fanenorm: spencer fane
- Domain
- spencerfane.com
Victim entity
- Name
- Keys Pathology Associates, PAnorm: keys pathology associates
Incident
- Discovered
- May 27, 2025
- Materiality determined
- —
- Notification sent
- Sep 5, 2025
- Affected individuals
- 26
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Third party
- via Genesis Billing Services, Inc.
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.