Harbor
bd_d4a34d6895ce7979 · schema v1 · pii pii-v1
Full breach record for Harbor →4 incidents on fileHarbor notified patients, employees, and board members of unauthorized access to its network between July 25 and August 1, 2025. The incident involved the exfiltration of PII (SSN, DL), PHI, and financial data. Harbor launched an investigation, sent notices via mail and website, and offered credit monitoring. No specific count of affected individuals was provided in this Montana filing.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 25, 2025
Begins
Aug 1, 2025
Discovered
Oct 24, 2025
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Nebraska State AGbd_02bb0b2f44a761b92025-10-24Verified
- Massachusetts State AGbd_18438c745531b7f22025-10-24Verified
- Maine State AGbd_2553d8403fd8364b2025-10-24Verified
- New Hampshire State AGbd_2f540137b6d032672025-10-24Verified
Show 3 more filings ↓Show fewer ↑up to 24d gap
- Vermont State AGbd_9a4998fa85b306a62025-10-24Verified
- Illinois State AGbd_cde758c48c991ef32025-10-01 · +23dCandidate
- HHS OCRbd_7bfe7b23f5f210c72025-09-30 · +24dVerified by operator
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Sep 30 (OH), last Oct 24 (MT) — a 24-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.