MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedDownstream VictimsMulti-Stage ChainIDENTITY_BASICPIILowContained
Columbia Medical Practice
bd_0d3025706b44e21b · schema v1 · pii pii-v1
Full breach record for Columbia Medical Practice →Columbia Medical Practice disclosed an external system breach (hacking) on 11/05/2025 where an unknown cyber actor installed a virus to lock files and exfiltrated data including names and Social Security numbers. Discovered on 03/31/2026. Six Maine residents were notified on 04/24/2026. The healthcare facility offered one year of credit monitoring and identity restoration via TransUnion.
Leak gap clock⏱ Leak >90d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by qilin about this victim predates this filing by 170 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_2d2d868255e5f739Leak Siteqilinfiled 2025-11-25(149d gap)Candidate
- bd_d270903e72841761Leak Siteqilinfiled 2025-11-05(170d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/78eb57c4-a3d1-4ab8-95de-385f536c0e3c.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 24, 2026
- Raw hash
- c42da8452a61344cac631f5e8062e174ef2ac60387702a7e6888fa046a0bcfd4
Reporting entity
- Name
- Columbia Medical Practicenorm: columbia medical practice
- Domain
- cmpractice.com
Victim entity
- Name
- Columbia Medical Practicenorm: columbia medical practice
- Domain
- cmpractice.com
Incident
- Discovered
- Mar 31, 2026
- Materiality determined
- —
- Notification sent
- Apr 24, 2026
- Affected individuals
- 6
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified US Department of Health and Human ServicesNotified federal law enforcement
- Third party
- via Cyberscout (TransUnion company)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- Leak >90dME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 31, 2026→ Filed with AG: Apr 24, 202624d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.