Heart South Cardiovascular Group
bd_c12dc0d5f533ec4e · schema v1 · pii pii-v1
Full breach record for Heart South Cardiovascular Group →4 incidents on fileHeart South Cardiovascular Group, PC notified Nebraska residents of a cybersecurity incident discovered on November 11, 2025, where an unauthorized party claimed to possess patient data. Forensic investigation found no network access or data theft, but a bad actor posted limited data on the dark web. Kroll was engaged to provide complimentary identity monitoring services to affected patients.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 11, 2025
Discovered
Apr 6, 2026
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siterhysidabd_2028c3f5990168862025-11-10 · +146dVerified by operator
Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_75ff5c082c82aced2026-04-06Verified
- Maine State AGbd_dc4e83aef803c8912026-04-06Verified
- New Hampshire State AGbd_718fd6945d5f19042026-04-13 · +7dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Apr 6 (AL), last Apr 13 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.