Sycamore Rehabilitation Services, Inc.
bd_cac06062a75e937e · schema v1 · pii pii-v1
Full breach record for Sycamore Rehabilitation Services, Inc. →Sycamore Rehabilitation Services, Inc. reported a cybersecurity incident where an unauthorized third party may have accessed employee mailbox accounts. The breach occurred between July 29, 2023, and August 9, 2023, and was discovered on September 21, 2023. The investigation determined that sensitive information for 3,414 individuals may have been exposed, including names, Social Security numbers, driver's licenses, financial account information, and medical data. The company sent notification letters to affected individuals on March 1, 2024, and offered complimentary identity theft protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 29, 2023
Begins
Sep 21, 2023
Discovered
Mar 18, 2024
Filed
vs. sector median
+15 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- HHS OCRbd_199994960da60bd82024-03-18Verified
- New Hampshire State AGbd_eaedb39c9720d83d2024-03-25 · +7dVerified
- Massachusetts State AGbd_9a37f2e575f6cf032024-03-26 · +8dVerified
- Indiana State AGbd_089e1625dfb7d7f12024-03-01 · +17dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Mar 1 (IN), last Mar 26 (MA) — a 25-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.