DisclosureLens
HackingHealthcareHealthcareVulnerability ExploitData ExfiltratedCustomer Data InvolvedGovernment IDIdentity (basic)HighContained

CRG Lynwood, LLC

bd_807a36cceac76c0c · schema v1 · pii pii-v1

Severity

High

Discovered

Jul 12, 2021

Filed

Jun 10, 2024

To disclose

35 months

Affected · nationwide

6,5661 in this filing

Linked

3 filings

Confidence

66%
Full breach record for CRG Lynwood, LLC

CRG Lynwood, LLC (d/b/a Lynwood Manor), a healthcare entity based in Michigan, reported an external system breach (hacking) occurring on July 12, 2021. The incident compromised the personal information of 6,566 individuals, including 1 Maine resident. Acquired data included names combined with driver's license numbers. The entity notified affected individuals in writing on June 7, 2024, and offered identity theft protection services.

Maine clockDiscovered Jul 12, 2021Filed with AG Jun 10, 20241064d ME AG >90d35 months discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 35 months / 1064 days

Jul 12, 2021

Begins

Jul 12, 2021

Discovered

Jun 10, 2024

Filed

vs. sector median

+139 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
New Hampshire State AGJun 10 · first
HHS OCRJun 10 · first
Maine State AGJun 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.