HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Carolina Arthritis
bd_8076b43f1a07995d · schema v1 · pii pii-v1
Full breach record for Carolina Arthritis →Carolina Arthritis Associates reported a data security incident occurring on September 27, 2024, involving unauthorized access to files containing personal information. The breach affected Maryland residents, with data types including names and government identifiers (SSN/driver's license). The company engaged forensic investigators, reported the incident to the FBI, and mailed notifications offering 12 months of credit monitoring and identity protection services via CyberScout.
Maryland clock✗ MD AG >90d22 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
A leak claim by threeam about this victim predates this filing by 125 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_afad31b5e423fe58Leak Sitethreeamfiled 2024-10-24(125d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_25b183630cee6006New Hampshire State AGfiled 2025-02-27Verified
- bd_3e3faec2dc9622c0Maine State AGfiled 2025-02-27Verified
- bd_47d1979d018b1d02HHS OCRfiled 2025-02-27Verified
- bd_5c4c73fe34204471Vermont State AGfiled 2025-02-27Verified
Show 1 more filing ↓Show fewer ↑
- bd_7f5415b879da3317Indiana State AGfiled 2025-02-27Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376425.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- 47f4a66bdb56cbd68f4c39b0b3075c00639d773c00b4ec291500a338a3e7d4eb
Reporting entity
- Name
- Carolina Arthritisnorm: carolina arthritis
- Domain
- carolinaarthritis.com
Victim entity
- Name
- Carolina Arthritisnorm: carolina arthritis
- Domain
- carolinaarthritis.com
Incident
- Discovered
- Sep 27, 2024
- Materiality determined
- —
- Notification sent
- Feb 27, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- MD AG >90dLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.