
Impact Melanoma Inc. disclosed to the New Hampshire Attorney General on Sept. 24, 2026, with one New Hampshire resident identified as potentially affected.
Impact Melanoma discovered the incident on May 26, 2026, and began notifying affected consumers on or about Sept. 21, 2026. The total number of individuals affected across the United States was not specified in the organization's disclosure.
According to the organization's notice to consumers, an unknown individual gained unauthorized access to two employee email inboxes at Impact Melanoma. The notification filed with the New Hampshire Attorney General described the affected accounts as "a limited number of email accounts." The unauthorized access occurred at some point before the organization detected the suspicious activity.
A subsequent forensic investigation and extensive manual document review determined on Sept. 10, 2026, that personal information belonging to at least one individual may have been accessed or acquired by the unknown individual. According to the notification, the data was potentially accessed or acquired before the breach was discovered. The exact date when the unauthorized access first began was not specified in the organization's disclosures.
The types of personal information potentially exposed in the breach included full names and Social Security numbers.
Social Security numbers are considered among the most sensitive forms of personally identifiable information because they can be used to open new financial accounts, file fraudulent tax returns or commit other forms of identity theft. The exposure of this type of information warrants careful and ongoing attention from anyone who receives a notification from the organization.
In its notification letter, Impact Melanoma stated that it has no evidence to date of any identity theft or financial fraud resulting from this incident. Nevertheless, the organization said it wanted to inform affected individuals and explain the steps it is taking to help safeguard personal information in its care. The notification also advised affected individuals to remain vigilant by regularly reviewing their financial account statements for any fraudulent or irregular activity.
To help protect those whose information may have been compromised, Impact Melanoma is offering 12 months of complimentary identity protection services through IDX, a data breach and recovery services provider. The services include credit monitoring, CyberScan monitoring, a $1,000,000 insurance reimbursement policy and fully managed identity theft recovery services. Affected individuals received an enrollment code in their notification letter, which they can use to sign up for the services online or with assistance from IDX.
In addition to the identity protection services, the organization provided affected individuals with contact information for the three major credit reporting agencies and the Federal Trade Commission. Impact Melanoma stated in its notice that protecting the privacy of personal information is a top priority, and that it continually evaluates and modifies its practices and internal controls to enhance the security and privacy of the data entrusted to its care.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)