Dermatology Associates
bd_808c94933cf678ad · schema v1 · pii pii-v1
Full breach record for Dermatology Associates →4 incidents on fileDermatology Associates notified the Massachusetts Attorney General of an unauthorized access incident. The organization became aware of suspicious activity on August 4, 2025. An investigation determined that an unauthorized actor accessed systems between June 4, 2025, and August 5, 2025. The incident potentially involved protected health information (PHI), including names, addresses, dates of birth, and Social Security numbers. The organization engaged third-party cybersecurity specialists, notified affected individuals via website and media, and is offering 24 months of credit monitoring. The investigation is contained.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 4, 2025
Begins
Aug 4, 2025
Discovered
Mar 4, 2026
Filed
vs. sector median
+18 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteanubisbd_07b8e25f7f3b2d112025-11-06 · +117dCandidate
Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_b8e34d45fafe61dd2026-03-04Verified by operator
- HHS OCRbd_2d22edc295ce74862025-10-03 · +152dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Oct 3 (KY), last Mar 4 (MA) — a 152-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.