HackingHealthcareHealthcareSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Ronald McDonald House of Dallas
bd_144a89df0e5b8a27 · schema v1 · pii pii-v1
Full breach record for Ronald McDonald House of Dallas →Ronald McDonald House of Dallas reported a data breach affecting 17,373 individuals, including 2 Maine residents, due to a security incident at their third-party vendor, Blackbaud, Inc. The breach occurred between February 7, 2020, and May 20, 2020, and was discovered on December 1, 2020. The compromised information included names combined with driver's license or non-driver identification card numbers. Affected individuals were notified on January 14, 2021, and offered one year of credit monitoring and identity theft protection services through Experian.
Maine clockDiscovered Dec 1, 2020 → Filed with AG Jan 14, 202144d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_dd4181dafb498d10Montana State AGfiled 2021-01-14Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/ab5ffb79-9b61-4cf7-bf25-1e884d41f0f0.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2021
- Raw hash
- a7c5d7aec410ed0beca38aa73bdb758ec0fc6b1c958a1cf8b2342816cdee7b2d
Reporting entity
- Name
- Ronald McDonald House of Dallasnorm: ronald mcdonald house of dallas
Victim entity
- Name
- Ronald McDonald House of Dallasnorm: ronald mcdonald house of dallas
- Industry
- Healthcarellm
Incident
- Discovered
- Dec 1, 2020
- Materiality determined
- —
- Notification sent
- Jan 14, 2021
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- ME AG >30d · 44d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 1, 2020→ Filed with AG: Jan 14, 202144d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.