DisclosureLens
HackingHealthcareHealthcareStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Laurel Eye Clinic

bd_12a9fc4af52fb881 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 26, 2025

Filed

Apr 22, 2026

To disclose

15 months

Affected

4state residents only

Linked

6 filings

Confidence

67%
Full breach record for Laurel Eye Clinic

Laurel Eye Clinic notified the New Hampshire Attorney General of a cybersecurity incident discovered on January 26, 2025. An unauthorized user obtained certain files containing names, financial account numbers, and routing numbers. Four New Hampshire residents were identified and notified on April 22, 2026. The clinic engaged forensic investigators, disconnected network access, and offered 12 months of credit monitoring.

Incident timeline

discovery → filing · 15 months / 451 days

Jan 26, 2025

Discovered

Apr 22, 2026

Filed

vs. sector median

+52 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filing

Filing propagation · 6 filings · 6 states

View merged incident ↗
Nebraska State AGApr 22 · first
Indiana State AGApr 22 · first
Massachusetts State AGApr 22 · first
Maine State AGApr 22 · first
HHS OCRApr 22 · first
New Hampshire State AGApr 22 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.