MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Frederick Health
bd_ddd4f7ddc23cf672 · schema v1 · pii pii-v1
Full breach record for Frederick Health →Frederick Health, a Maryland healthcare provider, disclosed a ransomware incident discovered on January 27, 2025. An unauthorized party accessed the network and copied files from a file share server, potentially affecting 13,239 Maryland residents. Data involved names, DOBs, SSNs, driver's license numbers, and financial account information. Frederick Health engaged forensic investigators, notified law enforcement, and mailed notices to affected residents on March 28, 2025, offering credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed13,239 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376814.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- ee6e475ee777ddca18c675b47d4e3bbcd737201a68de88c245286b61b05ccfd8
Reporting entity
- Name
- Frederick Healthnorm: frederick health
Victim entity
- Name
- Frederick Healthnorm: frederick health
Incident
- Discovered
- Jan 27, 2025
- Materiality determined
- —
- Notification sent
- Mar 28, 2025
- Affected individuals
- 13,239
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General's Office
Compliance
- Time to disclose
- 15 months(451 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.