DisclosureLens
HackingHealthcareHealthcareStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIPHIIdentity (basic)Health (basic)LowContained

ERMI

bd_6f3c9fcbecab88f2 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 25, 2025

Filed

May 26, 2026

To disclose

44 weeks

Affected

Not disclosed

Linked

8 filings

Confidence

65%
Full breach record for ERMI

ERMI LLC notified the California Attorney General of an incident where an unauthorized individual accessed employee email accounts. The breach occurred between February 15, 2025, and August 14, 2025, and was discovered on July 25, 2025. Personal information, including medical data, may have been accessed or removed. The company engaged external cybersecurity professionals and is offering credit monitoring services to affected individuals.

Incident timeline

undetected · 160 days
discovery → filing · 44 weeks / 305 days

Feb 15, 2025

Begins

Jul 25, 2025

Discovered

May 26, 2026

Filed

vs. sector median

+31 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 25d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing May 1 (IL), last May 29 (SC) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.