OHHackingHealthcareHealthcarePHIHigh
Harbor
bd_7bfe7b23f5f210c7 · schema v1 · pii pii-v1
Full breach record for Harbor →HHS OCR Breach Portal entry: Harbor (Ohio, Healthcare Provider) reported a Hacking/IT Incident affecting a Network Server on 2025-09-30. 216,000 individuals affected. No business associate involvement reported. No further narrative provided in the portal row.
HIPAA clock✓ HHS notified
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2553d8403fd8364bMaine State AGfiled 2025-10-24(24d gap)Verified
- bd_2f540137b6d03267New Hampshire State AGfiled 2025-10-24(24d gap)Verified
- bd_9a4998fa85b306a6Vermont State AGfiled 2025-10-24(24d gap)Verified
- bd_d4a34d6895ce7979Montana State AGfiled 2025-10-24(24d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 30, 2025
- Raw hash
- f3ba593c9e8f177ecd4b41db2039caf34a04eedc5e14416a0332dbe3e591c469
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Harbornorm: harbor
- Domain
- goharbor.io
Victim entity
- Name
- Harbornorm: harbor
- Domain
- goharbor.io
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 1, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 216,000
- Data types
- PHI
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 1, 2025→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.