CMS Companies
bd_a4067425fe79fa9c · schema v1 · pii pii-v1
Full breach record for CMS Companies →CMS Companies filed a supplemental notice with the New Hampshire AG regarding a July 20, 2021 malware incident. The breach affected 51 NH residents, exposing names, SSNs, and financial data. CMS engaged forensic specialists, notified law enforcement, and provided 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 20, 2021
Begins
Jul 20, 2021
Discovered
Feb 22, 2022
Filed
vs. sector median
+22 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Maine State AGbd_66dd757594b023502022-02-04 · +18dCandidate
- Indiana State AGbd_726c56ad0c3535392022-02-04 · +18dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Feb 4 (ME), last Feb 22 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.