HackingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Allwell Behavioral Health Services
bd_6c239ce3cc969d62 · schema v1 · pii pii-v1
Full breach record for Allwell Behavioral Health Services →Allwell Behavioral Health Services, a healthcare entity based in Zanesville, Ohio, reported an external system breach (hacking) occurring on March 2, 2022, and discovered on March 5, 2022. The incident compromised the names and driver's license numbers of 30,952 individuals, including 2 Maine residents. Notification was sent on May 23, 2022, offering 12 months of credit monitoring and ID theft recovery services.
Maine clockDiscovered Mar 5, 2022 → Filed with AG May 23, 202279d ⏱ ME AG >30d11 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1610d89e5dc2f00aNew Hampshire State AGfiled 2022-05-23Verified
- bd_8a31afbb18f198e7Montana State AGfiled 2022-05-23Verified
- bd_b5f444a97d3bf561HHS OCRfiled 2022-05-23Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c575381a-104c-4aca-b367-df996a00484a.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2022
- Raw hash
- 1051e2e94193b3faf6632afb60a3e3ad6bd4d12d30389352fdee78b710086e86
Reporting entity
- Name
- Allwell Behavioral Health Servicesnorm: allwell behavioral health
- Domain
- allwell.org
- Industry
- Healthcare
Victim entity
- Name
- Allwell Behavioral Health Servicesnorm: allwell behavioral health
- Domain
- allwell.org
- Industry
- Healthcare
Incident
- Discovered
- Mar 5, 2022
- Materiality determined
- —
- Notification sent
- May 23, 2022
- Affected individuals
- 30,952
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- ME AG >30d · 79dME resident >60d · 79d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 5, 2022→ Filed with AG: May 23, 202279d 30 days (soft) ME AG >30d Maine Discovered: Mar 5, 2022→ Notified: May 23, 202279d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.