HackingHealthcareHealthcareStolen CredentialsCapture App DataCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Andover Eye Associates
bd_5541a942b8c8518a · schema v1 · pii pii-v1
Full breach record for Andover Eye Associates →Andover Eye Associates, a healthcare provider in Andover, MA, experienced unauthorized access to two employee email accounts on May 28, 2025. The incident was discovered on November 4, 2025, following a review triggered by an alert on June 10, 2025. Potentially compromised information includes names and Social Security numbers. Seven Maine residents were affected out of 1,638 total. Andover notified HHS under HIPAA and offered 12-month credit monitoring through Epiq Global.
Maine clockDiscovered Nov 4, 2025 → Filed with AG Dec 31, 202557d ⏱ ME AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/030dba15-f58b-400d-9ffc-56012920694f.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2025
- Raw hash
- 054fc0d24f94f606f664aea79ed6242587d84d3262e2da76c5ab0b04cd313d83
Reporting entity
- Name
- Andover Eye Associatesnorm: andover eye associates
- Domain
- andovereyeinstitute.com
- Industry
- Healthcare
Victim entity
- Name
- Andover Eye Associatesnorm: andover eye associates
- Domain
- andovereyeinstitute.com
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Nov 4, 2025
- Materiality determined
- —
- Notification sent
- Dec 31, 2025
- Affected individuals
- 7
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified U.S. Department of Health and Human Services (HIPAA)Notified prominent media pursuant to HIPAANotified federal law enforcementNotified Maine Attorney General
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- ME AG >30d · 57d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 4, 2025→ Filed with AG: Dec 31, 202557d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.