DisclosureLens
HackingHealthcareHealthcareStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryPIIIdentity (basic)LowContained

Nephrology Associates Medical Group

bd_69f82657620eeced · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Mar 26, 2026

To disclose

Affected

Not disclosed

Confidence

80%
Full breach record for Nephrology Associates Medical Group2 incidents on file

Nephrology Associates Medical Group, a medical group based in Riverside, CA, discovered suspicious activity in an employee email account on or about May 20, 2025. An unauthorized individual may have accessed personal information stored in the account. The breach dates span May 19–22, 2025. The organization engaged cybersecurity experts, implemented additional security features, and is offering Kroll credit monitoring to affected individuals.

Incident timeline

May 19, 2025

Begins

Mar 26, 2026

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Nephrology Associates Medical Group — State AG breach notification · DisclosureLens