Steward Medical Group
bd_5fd4ec2d09548bc2 · schema v1 · pii pii-v1
Full breach record for Steward Medical Group →9 incidents on fileSteward Medical Group, Inc. notified the NH Attorney General of a data security incident involving one NH resident. On March 19, 2021, SMG discovered that its billing agent, MiraMed Global Services, inadvertently mailed protected health information (PHI) and PII (including SSN, DOB, name) to the wrong workers' compensation carrier (City of Boston). The error occurred during billing data transfer. SMG contacted the carrier, ensured data destruction/return, fixed the system error, and reviewed policies. The resident was notified on May 18, 2021, and offered 24 months of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 19, 2021
Discovered
May 26, 2021
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_443490f938e3ffae2021-05-21 · +5dVerified
- HHS OCRbd_5f9a081ac760ec932021-06-04 · +9dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing May 21 (MA), last Jun 4 (MA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.