A New Hampshire nonprofit that runs mental health and behavioral programs has told federal regulators that intruders reached the records of 49,540 people. NFI North, based in Contoocook, said in a substitute breach notice that suspicious activity was identified in its network on or around September 6, 2025, and that its data review did not conclude until July 6, 2026.
Exposed information includes names, addresses, birth dates, Social Security numbers, driver’s license numbers, financial account details, medical information and health insurance data. The organization said it brought in cybersecurity professionals and added technical safeguards after the incident.
Two more notices landed in the same week. PAMCAH-UA Local 675 Health and Welfare Fund in Honolulu, which administers benefits for union plumbers and fitters, found that employee email accounts were accessed between September 23 and October 9, 2025, exposing the personal and protected health information of 8,319 people, and it has started mailing letters. Indico Data Solutions, a Massachusetts company whose AI intake platform holds client health data, confirmed an incident on May 7, 2026, and is notifying 4,840 individuals whose names, addresses and Social Security numbers may have been exposed, with credit monitoring offered.
The months-long gap between the 2025 intrusions and these public notices shows how long scoping reviews can push disclosure, a delay pattern regulators have scrutinized. For healthcare organizations, the notices also underline that AI and fulfillment vendors handling protected health data are becoming a steady source of breach mailings.