Arbor Associates Inc
bd_4477dbc38992c443 · schema v1 · pii pii-v1
Full breach record for Arbor Associates Inc →Arbor Associates, Inc. issued a supplemental notice to the Washington AG regarding a ransomware incident. Unauthorized access occurred between April 15-17, 2025. The breach affected approximately 9,005 Washington residents, exposing PHI and PII including names, DOBs, and medical record numbers. Arbor engaged cybersecurity experts and implemented additional safeguards.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 15, 2025
Begins
Apr 17, 2025
Discovered
Jul 3, 2025
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Massachusetts State AGbd_15a5c87af98e6ebd2025-07-03Verified
- HHS OCRbd_19e14edfcd577e892025-07-03Verified
- Montana State AGbd_a984f051dd655e2f2025-07-03Verified
- California State AGbd_d13f3fd45725847a2025-07-03Verified
Show 6 more filings ↓Show fewer ↑up to 40d gap
- Illinois State AGbd_2139cdce40ed95232025-07-01 · +2dCandidate
- Vermont State AGbd_5c23d20e0ad3430d2025-07-17 · +14dVerified
- Oregon State AGbd_7e87e5d560735bef2025-07-17 · +14dVerified
- Montana State AGbd_90472ab9e6074d4a2025-08-08 · +36dVerified
- California State AGbd_b50fb3d4dec6d3c42025-08-08 · +36dVerified
- Texas State AGbd_a75ba824f7da509a2025-08-12 · +40dVerified
Filing propagation · 11 filings · 9 states
View merged incident ↗Pattern: first filing Jul 1 (IL), last Aug 12 (TX) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.