Esse Health
bd_ef0beb164e384a0f · schema v1 · pii pii-v1
Full breach record for Esse Health →Esse Health reported a cyber event where a cybercriminal gained access to its network on April 21, 2025, viewing and copying files containing patient information. The organization engaged forensic specialists, secured systems, notified law enforcement, and offered identity protection services. NextGen electronic medical records were not accessed.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 21, 2025
Begins
Apr 21, 2025
Discovered
Sep 10, 2025
Filed
vs. sector median
+8 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Vermont State AGbd_0f559e2e213759252025-06-30 · +72dCandidate
- Maine State AGbd_de426a2ba50bebf92025-06-30 · +72dVerified
- Massachusetts State AGbd_42902b01272db9572025-06-27 · +75dVerified
- Indiana State AGbd_8579359a35c782372025-06-25 · +77dVerified
Show 1 more filing ↓Show fewer ↑up to 82d gap
- HHS OCRbd_f1219c8e28ac0ec02025-06-20 · +82dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jun 20 (MO), last Sep 10 (VT) — a 82-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.