HackingHealthcareHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIPHILowResolved
Asheville Eye Associates, PLLC
bd_93dc0cb8a1a6d331 · schema v1 · pii pii-v1
Full breach record for Asheville Eye Associates, PLLC →On or around November 18, 2024, Asheville Eye Associates, PLLC experienced an external network security breach in which an unauthorized party gained access to and acquired files from their systems. The incident was fully investigated by April 14, 2025. Affected data may include name, address, Social Security Number, medical treatment information, and health insurance information. 147,116 individuals were affected total; 35 were Maine residents. Notifications were sent June 13, 2025.
Leak gap clock✗ Leak >180d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 207 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_8e9f39a1a6b44186Leak Sitedragonforcefiled 2024-12-28(167d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c4455141-8d8a-4179-8be8-49ce21a2a97f.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2025
- Raw hash
- b26250edc857aa4965c131a87a2349c07366feecb3bdb9f2ff68b69cc1388539
Reporting entity
- Name
- Asheville Eye Associates, PLLCnorm: asheville eye associates
- Domain
- ashevilleeye.com
- Industry
- Healthcare
Victim entity
- Name
- Asheville Eye Associates, PLLCnorm: asheville eye associates
- Domain
- ashevilleeye.com
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Apr 14, 2025
- Materiality determined
- Apr 14, 2025
- Notification sent
- Jun 13, 2025
- Affected individuals
- 35
- Data types
- PIIPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported to law enforcement
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- Leak >180dME AG >30d · 60d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 14, 2025→ Filed with AG: Jun 13, 202560d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.