HackingHealthcareHealthcareStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryPHIPIILowContained
Onsite Mammography
bd_c85f887b9fa8986b · schema v1 · pii pii-v1
Full breach record for Onsite Mammography →In October 2024, an unauthorized actor gained access to a single employee email account at Onsite Mammography LLC, a national healthcare imaging services provider. The intrusion was discovered on April 15, 2025 following a data analytics vendor review concluding February 21, 2025. PHI and PII of patients may have been exposed. The actor did not access other systems. 357,265 individuals were affected nationally; 32 Maine residents. Equifax credit monitoring (12 months) was offered.
Maine clockDiscovered Apr 15, 2025 → Filed with AG Apr 21, 20256d ✓ ME AG ≤30d6 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_a946536717595088Vermont State AGfiled 2025-04-21Verified
- bd_a96b83cee14ef51fHHS OCRfiled 2025-04-21Verified
- bd_b49795f765e873bcIndiana State AGfiled 2025-04-21Verified
- bd_c686ace3fe4924d6New Hampshire State AGfiled 2025-04-21Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/cfcef04c-bcbf-4dc0-8d5d-da411e5904be.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2025
- Raw hash
- 47f8b6c32fd9d467b5c529f30eaaf0cbbda968537cbea8bd1e547cad425167c6
Reporting entity
- Name
- Onsite Mammographynorm: onsite mammography
- Industry
- Healthcare
Victim entity
- Name
- Onsite Mammographynorm: onsite mammography
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Apr 15, 2025
- Materiality determined
- —
- Notification sent
- Apr 21, 2025
- Affected individuals
- 32
- Data types
- PHIPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 15, 2025→ Filed with AG: Apr 21, 20256d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.