Ellis Medicine
bd_857dcf594b69322b · schema v1 · pii pii-v1
Full breach record for Ellis Medicine →Ellis Medicine notified consumers that an unauthorized person accessed an employee email account between January 17, 2025, and January 24, 2025, and again between March 27, 2025, and April 5, 2025. The incident potentially exposed names and other personal/health information. Ellis Medicine reset passwords and MFA, engaged third-party investigators, and is offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 17, 2025
Begins
Jul 22, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_9c599feaafa2b2182025-07-22Verified
- Maine State AGbd_fbd9cdca777dc5872025-07-22Candidate
- Nebraska State AGbd_2afdc743245a36aa2025-07-17 · +5dVerified
- Indiana State AGbd_c92ff11a81b2e7092025-07-17 · +5dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 17 (NE), last Jul 22 (VT) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.