UnknownCustomer Data InvolvedData ExfiltratedPHIHEALTH_BASICIDENTITY_BASICLowContained
Arbor
bd_d13f3fd45725847a · schema v1 · pii pii-v1
Full breach record for Arbor →Arbor Associates, Inc. notified the California Attorney General of a data security incident where unauthorized access occurred between April 15 and April 17, 2025. The company became aware of unusual network activity on April 17, 2025. Affected data may include names, contact info, age, sex, DOB, service dates, CPT/diagnosis codes, medical record numbers, insurance names, and doctor names. Arbor engaged cybersecurity experts and implemented security enhancements.
California clockDiscovered Apr 17, 2025 → Notified Jul 3, 202577d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_4477dbc38992c443Washington State AGfiled 2025-07-03Candidate
- bd_a984f051dd655e2fMontana State AGfiled 2025-07-03Verified
- bd_5c23d20e0ad3430dVermont State AGfiled 2025-07-17(14d gap)Verified
- bd_7e87e5d560735befOregon State AGfiled 2025-07-17(14d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 40d gap
- bd_90472ab9e6074d4aMontana State AGfiled 2025-08-08(36d gap)Verified
- bd_b50fb3d4dec6d3c4California State AGfiled 2025-08-08(36d gap)Verified
- bd_a75ba824f7da509aTexas State AGfiled 2025-08-12(40d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-604990
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- eba5778a6e4aba8a883dde426174960f1b58bd63d74a6b4aaf58d79de54f21df
Reporting entity
- Name
- Arbornorm: arbor
- Domain
- arbor-education.com
Victim entity
- Name
- Arbornorm: arbor
- Domain
- arbor-education.com
Incident
- Discovered
- Apr 17, 2025
- Materiality determined
- —
- Notification sent
- Jul 3, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unknown
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- CA 60-day late · 77d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2025→ Notified: Jul 3, 202577d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.