DisclosureLens
HackingHealthcareTechnologyHealthcareData ExfiltratedCustomer Data InvolvedPHIHealth (basic)Identity (basic)LowContained

Clinical Registry Solutions

bd_b568d92392350290 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 9, 2026

Filed

Jul 29, 2026

To disclose

16 weeks

Affected

Not disclosed

Linked

10 filings

Confidence

65%
Full breach record for Clinical Registry Solutions

Clinical Registry Solutions, a data abstraction company assisting hospitals with medical registry reporting, experienced unauthorized access to its network on April 9, 2026. The company discovered a network disruption on that date, took systems offline, and retained cybersecurity specialists. Investigation revealed that certain files containing patient information, including protected health information (PHI) and personal data, may have been taken from the network. CRS reset passwords, implemented additional security measures, and reported the incident to federal law enforcement. No evidence of misuse was found.

Leak gap clock Leak >90d16 weeks discovery → filing

Incident timeline

discovery → filing · 16 weeks / 111 days

Apr 9, 2026

Begins

Apr 9, 2026

Discovered

Jul 29, 2026

Filed

vs. sector median

+4 wks slower

This filing is one of 10 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 111 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 48d gap

Filing propagation · 8 filings · 6 states

View merged incident ↗
California State AGJun 11 · first
New Hampshire State AGJun 11 · first
California State AG+48d · this page

Pattern: first filing Jun 11 (CA), last Jul 29 (CA) — a 48-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.