MalwareRansomwareData EncryptedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCriticalContained
Personal Touch Holding Corp.
bd_ca05f941e9f83152 · schema v1 · pii pii-v1
Full breach record for Personal Touch Holding Corp. →Personal Touch Holding Corp., a healthcare business associate, reported a ransomware incident affecting 753,107 Maine residents. The breach occurred between January 20-27, 2021, resulting in the encryption of data and exposure of names, government identifiers, and financial account numbers. Affected individuals received written notification and were offered 12 months of identity protection services.
Maine clockDiscovered Jan 27, 2021 → Filed with AG Mar 25, 202157d ⏱ ME AG >30d8 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
N1 · Nationwide count promoted
Affected · nationwide
93
ME slice (headline)
753,107· 809792.5% of total
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_291548b535923b50HHS OCRfiled 2021-03-26(1d gap)Verified
- bd_dc9b63375f188b7bMontana State AGfiled 2021-03-26(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/79e73e85-40e7-4c4f-aa0d-206e0d0cc530.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2021
- Raw hash
- 644efae2228cf2711d9f76c730d50280096b21e9b7d43f918223e5883e41c594
Reporting entity
- Name
- Personal Touch Holding Corp.norm: personal touch
Victim entity
- Name
- Personal Touch Holding Corp.norm: personal touch
Incident
- Discovered
- Jan 27, 2021
- Materiality determined
- —
- Notification sent
- Mar 26, 2021
- Affected individuals
- 753,107
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- ME AG >30d · 57d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 27, 2021→ Filed with AG: Mar 25, 202157d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.