HackingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Southern OB/GYN Associates
bd_cf6d8fec32195f46 · schema v1 · pii pii-v1
Full breach record for Southern OB/GYN Associates →Southern Illinois Ob-Gyn Associates, S.C. disclosed a data security incident discovered on November 24, 2025, involving unauthorized access to patient systems. A forensic investigation concluded in January 2026 confirmed unauthorized access to personal information, including government IDs and basic identity data. The entity engaged a third-party cybersecurity firm, secured the environment, and provided 24 months of credit monitoring services to affected individuals. The notification was filed with the Massachusetts Attorney General in April 2026.
Massachusetts clock✗ MA AG >90d27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3f59cfcaeefbf921HHS OCRfiled 2026-05-22(10d gap)Verified
- bd_a6b43a54b2fb784dNew Hampshire State AGfiled 2026-05-19(13d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-916-southern-illinois-ob-gyn-associates-sc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 392269df9ebcf51fd080e6b3e295a091013a376b7745a6771f7da2ffcb399beb
Reporting entity
- Name
- Southern OB/GYN Associatesnorm: southern ob gyn associates
- Domain
- sogamds.com
Victim entity
- Name
- Southern OB/GYN Associatesnorm: southern ob gyn associates
- Domain
- sogamds.com
Incident
- Discovered
- Nov 24, 2025
- Materiality determined
- —
- Notification sent
- Apr 28, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.