Twin Cities Pain Clinic
bd_8c26804cc3678661 · schema v1 · pii pii-v2
Full breach record for Twin Cities Pain Clinic →Twin Cities Pain Clinic experienced a Business Email Compromise (BEC) incident discovered on July 9, 2025. An unauthorized user accessed an employee's email account and limited SharePoint files. The breach potentially exposed personal information including names, dates of birth, Social Security numbers, financial account information, and health information. No evidence was found that personal information was downloaded or misused. The clinic engaged forensic investigators, reset credentials, and is offering 12 months of credit monitoring services to affected individuals. The notification was sent on September 4, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 9, 2025
Discovered
Sep 4, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_67590721629a1b882025-09-04Verified
- Massachusetts State AGbd_9550ecf2f004bdc32025-09-04Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.