MalwareHealthcareHealthcareRansomwareRansom DemandedData EncryptedCustomer Data InvolvedDelayed DiscoveryPIILowContained
Teton Orthopaedics
bd_380dfa6945c3224e · schema v1 · pii pii-v1
Full breach record for Teton Orthopaedics →Teton Orthopaedics, a healthcare provider in Jackson, WY, experienced a ransomware incident between January 16, 2024, and March 25, 2024, discovered on March 25, 2024. A third-party forensic investigation confirmed the breach. Personal information of approximately 13,409 individuals (9 Maine residents) may have been affected. Consumer notifications were sent December 13, 2024. IDX identity protection services (12 months) were offered to affected individuals.
Maine clockDiscovered Mar 25, 2024 → Filed with AG Jan 3, 2025284d ✗ ME AG >90d41 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 283 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_330860355eef7774Leak Sitedragonforcefiled 2024-03-25(283d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_9099b25a452e6baaHHS OCRfiled 2022-05-17(962d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/16b8aab5-8207-41e2-b572-ee45e2a786ea.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 3, 2025
- Raw hash
- b540ca15b5c5ce5eca4ebda38f724546e4e5258d3ed7f3ff9f1c630fa1956767
Reporting entity
- Name
- Teton Orthopaedicsnorm: teton orthopaedics
- Domain
- tetonortho.com
- Industry
- Healthcare
Victim entity
- Name
- Teton Orthopaedicsnorm: teton orthopaedics
- Domain
- tetonortho.com
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Mar 25, 2024
- Materiality determined
- —
- Notification sent
- Dec 13, 2024
- Affected individuals
- 9
- Data types
- PII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 41 weeks(284 days from discovery to filing)
- Compliance flags
- ME AG >90d · 284dME resident >180d · 263dLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 25, 2024→ Filed with AG: Jan 3, 2025284d 90 days ME AG >90d Maine Discovered: Mar 25, 2024→ Notified: Dec 13, 2024263d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.