HackingCustomer Data InvolvedData ExfiltratedPHIIDENTITY_BASICHEALTH_BASICLowContained
Arbor
bd_b50fb3d4dec6d3c4 · schema v1 · pii pii-v1
Full breach record for Arbor →Arbor Associates, Inc. disclosed a data security incident where unauthorized access occurred between April 15 and April 17, 2025. The company became aware of unusual network activity on April 17, 2025. Affected data included protected health information (PHI) such as names, contact info, age, sex, date of birth, service dates, CPT/diagnosis codes, medical record numbers, insurance names, and doctor names. This is a supplemental notification. Arbor engaged cybersecurity experts and implemented enhanced security measures.
California clockDiscovered Apr 17, 2025 → Notified Aug 8, 2025113d ✗ CA 60-day late16 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_90472ab9e6074d4aMontana State AGfiled 2025-08-08Verified
- bd_a75ba824f7da509aTexas State AGfiled 2025-08-12(4d gap)Verified
- bd_5c23d20e0ad3430dVermont State AGfiled 2025-07-17(22d gap)Verified
- bd_7e87e5d560735befOregon State AGfiled 2025-07-17(22d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 36d gap
- bd_4477dbc38992c443Washington State AGfiled 2025-07-03(36d gap)Candidate
- bd_a984f051dd655e2fMontana State AGfiled 2025-07-03(36d gap)Verified
- bd_d13f3fd45725847aCalifornia State AGfiled 2025-07-03(36d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606902
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2025
- Raw hash
- 73b8a1d90cd9197bddbf2063d43cd0e00a383b44d84ce91987c690d21d181699
Reporting entity
- Name
- Arbornorm: arbor
- Domain
- arbor-education.com
Victim entity
- Name
- Arbornorm: arbor
- Domain
- arbor-education.com
Incident
- Discovered
- Apr 17, 2025
- Materiality determined
- —
- Notification sent
- Aug 8, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 16 weeks(113 days from discovery to filing)
- Compliance flags
- CA 60-day late · 113d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2025→ Notified: Aug 8, 2025113d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.