Three Rivers Provider Network
ent_8106323d478ef7ee613b54d2
Disclosures
9
State AG · HHS OCR · 4 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
16,584
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Three Rivers Provider Network
- Normalized
- three rivers provider network— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- ⛰️New Hampshire State AGas victim2023-07-28
Three Rivers Provider Network reported a supplemental breach notification to New Hampshire regarding unauthorized access to an employee email account. The incident occurred June 2-3, 2022, and was discovered on June 3, 2022. Personal information of 9 NH residents was impacted. TRPN secured the account, engaged forensic experts, and offered credit monitoring.
- 🐻California State AGas victim2023-07-21
Three Rivers Provider Network identified unauthorized access to an employee email account on June 3, 2022. The breach, which occurred on June 2, 2022, potentially exposed personal information including names, addresses, SSNs, and protected health information (PHI) such as treatment and diagnosis data. The company secured the account and is offering credit monitoring.
- 🦞Maine State AGas victim2023-07-21
Three Rivers Provider Network experienced an external system breach (hacking) on 06/02/2022, discovered on 08/17/2022. The incident compromised names and Social Security Numbers of 16,584 individuals, including 6 Maine residents. Written notification was sent on 10/15/2022, offering 24 months of Equifax Complete Premier identity protection services.
- CALIFORNIAHHS OCRas victim2022-12-19
Three Rivers Provider Network, a HIPAA business associate based in California, reported to HHS OCR that an employee fell victim to an email phishing scheme, compromising the PHI of 4,725 individuals. Compromised data included names, addresses, dates of birth, Social Security numbers, claims information, health insurance information, diagnoses, medications, and other treatment information. The BA notified HHS, affected individuals, and the media, implemented additional administrative and technical safeguards, and retrained staff.
- 🐻California State AGas victim2022-11-09
On June 3, 2022, Three Rivers Provider Network (TRPN) identified unauthorized access to one employee email account by an unauthorized party. The account was immediately secured. On August 17, 2022, TRPN determined that personal information of affected individuals may have been accessed. TRPN offered 24-month complimentary Equifax credit monitoring to affected individuals. No financial account or credit card data was involved.
- 🦞Maine State AGas victim2022-11-09
Three Rivers Provider Network reported an external system breach (hacking) that occurred between June 2 and June 3, 2022. The breach was discovered on August 17, 2022. The incident affected 3 Maine residents. In response, the company offered 24 months of identity theft protection services.
- 🦬Montana State AGas victim2022-11-05
Three Rivers Provider Netowork reported a data breach to the Montana Attorney General. The breach was reported on 2022-11-05. The breach occurred on 6/3/2022. 5 Montana residents were affected.
- 🦞Maine State AGas victim2022-10-28
Three Rivers Provider Network, a healthcare organization, reported an external system breach (hacking) to the Maine Attorney General. The breach occurred on June 2, 2022, was discovered on August 17, 2022, and affected 2 Maine residents. Consumer notifications were sent on October 15, 2022, and affected individuals were offered identity theft protection services through Equifax CompleteTM Premier.
- 🦞Maine State AGas victim2022-10-21
Three Rivers Provider Network, a healthcare organization, reported a data breach affecting 737 individuals, including 2 Maine residents. The breach, described as an external system breach (hacking), occurred on June 2, 2022, and was discovered on August 17, 2022. The company began notifying affected individuals on October 15, 2022, and offered 24 months of identity theft protection services through Equifax.