DisclosureLens
HackingHealthcareData ExfiltratedCustomer Data InvolvedFinancial accountHealth (basic)Identity (basic)Government IDPCIMediumContained

Optalis Management Solutions

bd_d0ddbee6dbc4ef51 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jun 29, 2026

To disclose

Affected

20state residents only

Linked

4 filings

Confidence

66%
Full breach record for Optalis Management Solutions

Optalis Management Solutions notified Massachusetts residents of unauthorized access to its network between April 14 and April 19, 2025. The investigation concluded on June 10, 2026, revealing that data including names, SSNs, driver's license numbers, financial account information, and medical treatment/diagnosis information was removed from the network. The company engaged outside cybersecurity professionals and is offering identity theft protection services through IDX. No specific discovery date was provided in the notice.

Incident timeline

Apr 14, 2025

Begins

Jun 29, 2026

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Nebraska State AGJun 29 · first
HHS OCRJun 29 · first
Massachusetts State AGJun 29 · first · this page

Pattern: first filing Jun 29 (NE), last Jul 10 (NH) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.