HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Merritt Healthcare Advisors
bd_f0e65cfa063cb114 · schema v1 · pii pii-v1
Full breach record for Merritt Healthcare Advisors →Merritt Healthcare Advisors notified the NH Attorney General of a data security incident involving unauthorized access to an employee's email account. Access occurred between July 30 and August 25, 2022. Discovery was made on November 30, 2022. One NH resident's PII (name, SSN) was exposed. No evidence of misuse. Notification sent March 14, 2023.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d9a9b56c70539fb8California State AGfiled 2023-03-20Candidate
- bd_1d3c5b12a75d08b6HHS OCRfiled 2023-03-15(5d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/merritt-healthcare-advisors-20230320.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2023
- Raw hash
- 810ae7fe3503a5638125212f90c8ab9193b8ec527215ec75d0c17ee789a5accf
Reporting entity
- Name
- Merritt Healthcare Advisorsnorm: merritt healthcare advisors
Victim entity
- Name
- Merritt Healthcare Advisorsnorm: merritt healthcare advisors
Incident
- Discovered
- Nov 30, 2022
- Materiality determined
- —
- Notification sent
- Mar 14, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified Office of the Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.