DisclosureLens
AccidentalHealthcareProfessional ServicesHealthcareMisdeliveryCustomer Data InvolvedIdentity (basic)Government IDPIIMediumContained

Boston Area Rape Crisis Center

bd_daf7de9273306cc7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jan 16, 2026

To disclose

Affected

Not disclosed

Confidence

65%
Full breach record for Boston Area Rape Crisis Center

Boston Area Rape Crisis Center (BARCC) notified the Massachusetts Attorney General of an inadvertent disclosure of personal information caused by an employee's violation of data security policies. The incident involved the misdelivery of data to an unintended recipient. BARCC terminated the responsible employee and attempted to contact the recipient to mitigate the exposure. The organization is retraining employees on data security protocols. The breach likely involved PII including names, addresses, and potentially Social Security numbers, given the context of credit freeze instructions included in the notice.

Incident timeline — partial

? — ?

Breach window unknown

Jan 16, 2026

Filed

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.