DisclosureLens
HackingHealthcareHealthcareData ExfiltratedBusiness Associate (HIPAA)Downstream VictimsCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)CriticalContained

MCG Health, LLC

bd_a0380ae2d23fe355 · schema v1 · pii pii-v1

Severity

Critical

Discovered

Mar 25, 2022

Filed

Jun 21, 2022

To disclose

13 weeks

Affected · nationwide

1,100,0001 in this filing

Linked

11 filings

Confidence

50%
Full breach record for MCG Health, LLC

MCG Health, a HIPAA business associate, discovered on March 25, 2022, that an unauthorized party had obtained personal and health information of its customers' patients and members. The data may have been acquired around February 25-26, 2020. The compromised information included names, Social Security numbers, medical codes, postal addresses, telephone numbers, email addresses, dates of birth, and gender. In response, MCG engaged a forensic investigation firm, notified the FBI, enhanced its system security, and offered two years of identity protection and credit monitoring services to the affected individuals.

Maine clockDiscovered Mar 25, 2022Filed with AG Jun 21, 202288d ME AG >30d13 weeks discovery → filing

Incident timeline

undetected · 759 days
discovery → filing · 13 weeks / 88 days

Feb 25, 2020

Begins

Mar 25, 2022

Discovered

Jun 21, 2022

Filed

vs. sector median

on median

This filing is one of 11 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 171d gap

Filing propagation · 11 filings · 8 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Jul 8 (NH) — a 188-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.