HackingHealthcareHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
The Cooper Health System
bd_e7c6f6c60497b58e · schema v1 · pii pii-v1
Full breach record for The Cooper Health System →The Cooper Health System, a healthcare organization headquartered in Camden, NJ, experienced an external system breach (hacking) in May 2024 involving unauthorized access to its network. The breach was discovered on March 26, 2025, after a thorough investigation with cybersecurity experts. Affected data included names and Social Security numbers of 57,412 individuals total, with 1 Maine resident affected. Notifications were sent May 23, 2025. IDX identity protection services were offered.
Maine clockDiscovered Mar 26, 2025 → Filed with AG May 23, 202558d ⏱ ME AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0e52e3d43f302b7cNew Hampshire State AGfiled 2025-05-23Verified
- bd_12fc54c120493147Indiana State AGfiled 2025-05-23Verified
- bd_1334d8b37970129dHHS OCRfiled 2025-05-23Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/00e705cf-30ba-4dd1-aa72-82e50be98ac9.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2025
- Raw hash
- ee442738404ecc9dd36b2dc29d073b1dd8e6752f0a30f02fcf4203f2ad022205
Reporting entity
- Name
- The Cooper Health Systemnorm: the cooper health system
- Industry
- Healthcare
Victim entity
- Name
- The Cooper Health Systemnorm: the cooper health system
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Mar 26, 2025
- Materiality determined
- —
- Notification sent
- May 23, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Maine Attorney General notified May 23, 2025
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- ME AG >30d · 58d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 26, 2025→ Filed with AG: May 23, 202558d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.