HackingHealthcareHealthcareVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsPIIIDENTITY_GOVERNMENTMediumContained
North Star Fertility Partners LLC
bd_13faa24541f895e4 · schema v1 · pii pii-v1
Full breach record for North Star Fertility Partners LLC →North Star Fertility Partners LLC notified the Maine AG of a data breach originating at a third-party vendor, Salesloft, which allowed unauthorized access to a Salesforce-hosted database between August 12–17, 2025. The incident reportedly affected hundreds of organizations. Northstar determined on January 14, 2026 that the database contained the name and driver's license number of one Maine resident. Internal systems were not accessed. One-year Kroll credit monitoring offered.
Maine clockDiscovered Jan 14, 2026 → Filed with AG Feb 13, 202630d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_37c68213fcce6b4eIndiana State AGfiled 2026-02-13Verified by operator
- bd_ff30be6a21314df6New Hampshire State AGfiled 2026-02-13Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/5be9d38d-053f-4d43-bdc0-d07bc6559cd3.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 13, 2026
- Raw hash
- 44f1a033a8c13d7a5a48b7cecd99b6a88ab3798ba853225b0a2fca09e449f2ef
Reporting entity
- Name
- North Star Fertility Partners LLCnorm: north star fertility
Victim entity
- Name
- North Star Fertility Partners LLCnorm: north star fertility
- Industry
- Healthcarellm
Incident
- Discovered
- Jan 14, 2026
- Materiality determined
- Jan 14, 2026
- Notification sent
- Feb 13, 2026
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 14, 2026→ Filed with AG: Feb 13, 202630d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.