Ellis Medicine
bd_2afdc743245a36aa · schema v1 · pii pii-v2
Full breach record for Ellis Medicine →Ellis Medicine notified affected individuals in Nebraska and other states that an employee email account was accessed by an unauthorized person between January 17, 2025, and April 5, 2025. The incident involved suspicious activity on an employee email account, likely via phishing. Ellis Medicine reset passwords, reset MFA, engaged third-party investigators, and offered 12 months of credit monitoring services. The specific data elements at risk were placeholders in the template, but generally included names and potentially government IDs.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 17, 2025
Begins
Jan 17, 2025
Discovered
Jul 17, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_c92ff11a81b2e7092025-07-17Verified
- Vermont State AGbd_857dcf594b69322b2025-07-22 · +5dVerified
- Massachusetts State AGbd_9c599feaafa2b2182025-07-22 · +5dVerified
- Maine State AGbd_fbd9cdca777dc5872025-07-22 · +5dCandidate
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 17 (IN), last Jul 22 (ME) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.