Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoverySupply Chain (3P Vendor)IDENTITY_BASICHEALTH_BASICLowContained
SurgCenter of Western Maryland
bd_890738ac3815cb9d · schema v1 · pii pii-v1
Full breach record for SurgCenter of Western Maryland →SurgCenter of Western Maryland, LLC notified the Maryland Attorney General of a security incident involving former owner Precision Orthopedics Management. A phishing email sent to Precision contained an attachment with patient names, DOBs, and treatment info for 354 individuals. The incident occurred in September 2024, but was discovered by Precision only after they sold SurgCenter. 270 Maryland residents were not previously notified and are receiving notice now.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed354 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376968.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 797ed9fb6c2ca46c3ab0ee6872836582b1207a4a26b96d0dccb460def129c3bd
Reporting entity
- Name
- SurgCenter of Western Marylandnorm: surgcenter of western maryland
- Domain
- scwesternmd.com
Victim entity
- Name
- SurgCenter of Western Marylandnorm: surgcenter of western maryland
- Domain
- scwesternmd.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 31, 2025
- Affected individuals
- 354
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.