HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Lifespan Physicians Group of Massachusetts, Inc.
bd_e3709429c223e475 · schema v1 · pii pii-v1
Full breach record for Lifespan Physicians Group of Massachusetts, Inc. →Lifespan Physician Group (dba Brown Health Medical Group-MA) disclosed a data breach affecting a historic file server at its Hawthorn location. Unauthorized access occurred between Dec 15-16, 2025, discovered on Dec 16, 2025. The EHR system was not impacted. Potentially affected data includes demographic info, SSNs, driver's licenses, financial account numbers, and medical/HR records. Notices were sent July 16, 2026, offering two years of Experian IdentityWorks. Law enforcement was notified.
Massachusetts clock✗ MA AG >90d28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1151-lifespan-physician-group-of-massachusetts-inc-dba-brown-health-medical-group-ma/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- 96eac009b9427a27049a855f9e9e0a1d12d414f0b624c573f07eb3497bbb09a4
Reporting entity
- Name
- Lifespan Physicians Group of Massachusetts, Inc.norm: lifespan physicians group of massachusetts
Victim entity
- Name
- Lifespan Physicians Group of Massachusetts, Inc.norm: lifespan physicians group of massachusetts
Incident
- Discovered
- Dec 16, 2025
- Materiality determined
- —
- Notification sent
- Jul 16, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified law enforcement about the incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(197 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.