HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIHighContained
Coös County Family Health
bd_f14806bbae507beb · schema v1 · pii pii-v1
Full breach record for Coös County Family Health →Coos County Family Health Services notified the NH Attorney General on Oct 9, 2025, of a July 9, 2025 incident involving unauthorized access to servers. Approximately 35,609 NH residents were affected. Compromised data included names, DOBs, SSNs, medical IDs, and PHI. The organization engaged forensic investigators, notified law enforcement and HHS, and offered 12 months of credit monitoring.
Leak gap clock⏱ Leak >90d13 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by runsomewares about this victim predates this filing by 91 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4157a034d7aa6a46Vermont State AGfiled 2025-10-09Verified
- bd_baf9b9fa162a0aaaMaine State AGfiled 2025-10-09Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/coos-county-family-health-20251009.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2025
- Raw hash
- e395697a8af8f808a90f829cf5332a87e0ee277a72d1c12c3a56dee024f4b138
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Coös County Family Healthnorm: coos county family health
- Domain
- coosfamilyhealth.org
Incident
- Discovered
- Jul 9, 2025
- Materiality determined
- —
- Notification sent
- Oct 9, 2025
- Affected individuals
- 35,609
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementNotified the U.S. Department of Health and Human ServicesNotified relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.