HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Nationwide Recovery Services, Inc.
bd_fc5e851b479bd88e · schema v1 · pii pii-v1
Full breach record for Nationwide Recovery Services, Inc. →Ruffolo, Hooper & Associates (RHA), a healthcare provider, notified consumers of a data breach affecting data held by third-party vendor Nationwide Recovery Services (NRS). NRS experienced unauthorized access to its network between July 5-11, 2024. Impacted data included names, addresses, SSNs, DOBs, and PHI (facility names, dates of service, insurance info). RHA is offering 12 months of credit monitoring. NRS is implementing additional cybersecurity measures.
Vermont clock✗ VT AG >45 bday46 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_c4fee33645d310a0Vermont State AGfiled 2025-05-23(2d gap)Verified
- bd_16344af9ac358a81California State AGfiled 2025-06-06(16d gap)Candidate
- bd_4063c2b887187bd4Vermont State AGfiled 2025-06-06(16d gap)Verified
- bd_f716fd72481985a8New Hampshire State AGfiled 2025-06-06(16d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-05-21-physicians-independent-management-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 21, 2025
- Raw hash
- dc98b21eb0e9b1559c08e45845c2ce95f87f32bd55e6f9e85908bc66f97cfce6
Reporting entity
- Name
- Ruffolo, Hooper & Associates, MD, PAnorm: ruffolo hooper associates md
Victim entity
- Name
- Nationwide Recovery Services, Inc.norm: nationwide recovery
Incident
- Discovered
- Jul 5, 2024
- Materiality determined
- —
- Notification sent
- May 19, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Nationwide Recovery Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 46 weeks(320 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.