HackingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Texas Centers for Infectious Disease Associates
bd_f24ff419e5b04a9e · schema v1 · pii pii-v1
Full breach record for Texas Centers for Infectious Disease Associates →Texas Centers for Infectious Disease Associates (TCIDA) notified the New Hampshire Attorney General on June 26, 2025, of a data security incident affecting 1 NH resident. TCIDA detected unusual network activity on July 19, 2024, which was linked to a compromise of a former third-party billing vendor. The incident may have exposed names, SSNs, DOBs, driver's license numbers, and medical/insurance information. TCIDA engaged forensic experts, notified the FBI, and provided identity protection services to affected individuals.
Leak gap clock✗ Leak >180d49 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by bianlian about this victim predates this filing by 342 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_895aee4823c3f465Leak Sitebianlianfiled 2024-08-14(316d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_7b4685cd6cce0dcbIndiana State AGfiled 2025-06-26Verified
- bd_e72fc5733339e5cdHHS OCRfiled 2025-06-30(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/texas-centers-disease-20250626.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2025
- Raw hash
- 86c052c82b8c40876e4378771c04524ec3cd9877807bb7846603263d9e3793c5
Reporting entity
- Name
- Texas Centers for Infectious Disease Associatesnorm: texas centers for infectious disease associates
- Domain
- texascentersid.com
Victim entity
- Name
- Texas Centers for Infectious Disease Associatesnorm: texas centers for infectious disease associates
- Domain
- texascentersid.com
Incident
- Discovered
- Jul 19, 2024
- Materiality determined
- Jun 17, 2025
- Notification sent
- Jun 26, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation of the incident and will provide whatever cooperation is necessary to hold the perpetrators accountable
- Initial access
- supply_chain
Compliance
- Time to disclose
- 49 weeks(342 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.