HackingHealthcareHealthcareCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Forward, The National Databank for Rheumatic Diseases
bd_dee6aa8ce0cbab6b · schema v1 · pii pii-v1
Full breach record for Forward, The National Databank for Rheumatic Diseases →Forward, The National Databank for Rheumatic Diseases, a non-profit based in Wichita, KS, experienced unauthorized access to its network between March 17–22, 2025. The breach was discovered on June 19, 2025. Affected data for Maine residents (38 individuals) includes name, address, and Social Security number. Forward notified affected individuals on July 22, 2025, and offered 24-month credit monitoring via CyberScout/TransUnion.
Maine clockDiscovered Jun 19, 2025 → Filed with AG Jul 22, 202533d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_009089fe50437da3Vermont State AGfiled 2025-07-22Verified
- bd_be901a955d21e750Indiana State AGfiled 2025-07-22Verified
- bd_bf1fa1bdda078a66New Hampshire State AGfiled 2025-07-22Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/ddfce055-9b58-4f64-bb43-fc3bf0af3059.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2025
- Raw hash
- aa085a2cd9af451aa6c822756c39b6a2f22c153bec396cfffc8f4452ead8fac7
Reporting entity
- Name
- Forward, The National Databank for Rheumatic Diseasesnorm: forward the national databank for rheumatic diseases
- Industry
- Non-Profit
Victim entity
- Name
- Forward, The National Databank for Rheumatic Diseasesnorm: forward the national databank for rheumatic diseases
- Industry
- Non-Profit
- Industry
- Healthcarellm
Incident
- Discovered
- Jun 19, 2025
- Materiality determined
- —
- Notification sent
- Jul 22, 2025
- Affected individuals
- 38
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Written notice provided to Maine AG and three major consumer reporting agencies (Equifax, Experian, TransUnion)
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- ME AG >30d · 33d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 19, 2025→ Filed with AG: Jul 22, 202533d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.