CSIDB logo
Incident

Atlantic Digestive Specialists

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-10-05 01:11

Linked entities

Victim
Atlantic Digestive Specialists
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Atlantic Digestive Specialists detected suspicious activity on its network and engaged cybersecurity experts to investigate. The investigation determined that unauthorized access occurred over a brief interval, and a subsequent review confirmed that personal and protected health information had been accessed. After the review concluded, the provider began notifying affected individuals about the potential exposure of their data.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Atlantic Digestive Specialists, a private gastroenterology practice in New Hampshire with clinics in Somersworth, Portsmouth, and Hampton, detected suspicious network activity in March 2026. They engaged cybersecurity experts to investigate. The investigation determined that unauthorized access occurred between March 16 and March 17, 2026. A review concluding in August 2026 confirmed that personal and protected health information was involved. The practice began notifying affected individuals on September 30, 2026. They also reported the incident to state regulators. The notice indicated that at least 51 Rhode Island residents received notification letters. The total number of affected individuals has not been publicly confirmed. The attacker's identity has not been publicly disclosed.

The review indicated that the compromised information varied by individual. It could include names, Social Security numbers, driver's license or state ID numbers, and dates of birth. Financial account and payment card details were also potentially exposed. Passport numbers, taxpayer and alien registration numbers may have been part of the data. Health data such as clinical information, diagnoses, medical histories and record numbers were at risk. Treatment and prescription information, Medicaid/Medicare numbers, provider names, and health insurance policy numbers were also included. Usernames and passwords were among the identifiers possibly compromised.

Affected individuals face potential risk of identity theft and fraud. The practice established a toll-free help line (1-866-200-0962) operating Monday–Friday from 9:00 a.m. to 9:00 p.m. Eastern Time for inquiries. The state regulator notification satisfies reporting requirements. The national class action law firm Edelson Lechtzin LLP is investigating possible class action claims. The investigation concerns patients whose personal and protected health information may have been exposed. The outcome of that legal inquiry remains pending.

Sources

Sources available to members: 1 source.

CSIDB