UnknownOtherIDENTITY_GOVERNMENTPHIPIIHigh
COVENANT HEALTH
bd_95ce0e0243eda112 · schema v1 · pii pii-v1
Full breach record for COVENANT HEALTH →Covenant Health, Inc. based in Andover, Massachusetts, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-05-26 and reported on 2026-01-05. 1,101 Texas residents were affected. 478,188 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
Texas clock✗ TX AG >30d32 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_9f5aba5bf6f7a978California State AGfiled 2026-01-02(3d gap)Candidate
- bd_e35a31c1ca87c68cMontana State AGfiled 2026-01-02(3d gap)Verified
- bd_0201f6c42742ffa2New Hampshire State AGfiled 2025-12-31(5d gap)Verified
- bd_072a28e8c90a0e6bMaine State AGfiled 2025-12-31(5d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_ef41caaf4af9cbfeVermont State AGfiled 2025-12-31(5d gap)Verified
Source provenance
- Source URL
- https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0004772
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2026
- Raw hash
- 59e6e662ce1ee2c1c5a83099bee65a7e2e00e206c416f444b418e9a952380655
Reporting entity
- Name
- COVENANT HEALTHnorm: covenant health
Victim entity
- Name
- COVENANT HEALTHnorm: covenant health
- Industry
- Otherllm
Incident
- Discovered
- May 26, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,101
- Data types
- IDENTITY_GOVERNMENTPHIPII
- Attack vector
- Unknown
- Threat actor
- External
Compliance
- Time to disclose
- 32 weeks(224 days from discovery to filing)
- Compliance flags
- TX AG >30d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.