HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
CRG Lynwood, LLC
bd_807a36cceac76c0c · schema v1 · pii pii-v1
Full breach record for CRG Lynwood, LLC →CRG Lynwood, LLC (d/b/a Lynwood Manor), a healthcare entity based in Michigan, reported an external system breach (hacking) occurring on July 12, 2021. The incident compromised the personal information of 6,566 individuals, including 1 Maine resident. Acquired data included names combined with driver's license numbers. The entity notified affected individuals in writing on June 7, 2024, and offered identity theft protection services.
Maine clockDiscovered Jul 12, 2021 → Filed with AG Jun 10, 20241064d ✗ ME AG >90d35 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_605c836d0f7905f0New Hampshire State AGfiled 2024-06-10Verified
- bd_9e946490177e4566HHS OCRfiled 2024-06-10Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/fd49e982-65fd-46ee-8b9e-0092dd24a4ed.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2024
- Raw hash
- a9e87523d3f72f1f1abedc2d2435450d64739c8e993d2e4daa070f767da67d41
Reporting entity
- Name
- CRG Lynwood, LLCnorm: crg lynwood
- Industry
- Healthcare
Victim entity
- Name
- CRG Lynwood, LLCnorm: crg lynwood
- Industry
- Healthcare
Incident
- Discovered
- Jul 12, 2021
- Materiality determined
- —
- Notification sent
- Jun 7, 2024
- Affected individuals
- 6,566
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 35 months(1064 days from discovery to filing)
- Compliance flags
- ME AG >90d · 1064dME resident >180d · 1061d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jul 12, 2021→ Filed with AG: Jun 10, 20241064d 90 days ME AG >90d Maine Discovered: Jul 12, 2021→ Notified: Jun 7, 20241061d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.