HackingCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Mountain Laurel Dermatology
bd_f23d584a0aa53017 · schema v1 · pii pii-v1
Full breach record for Mountain Laurel Dermatology →Mountain Laurel Dermatology notified consumers of a data security incident involving unauthorized access to an external cloud-based network system. The incident, detected on May 12, 2025, potentially exposed names, check images, and medical treatment or diagnosis information. The breach did not involve the electronic medical records system. The practice engaged independent experts and is implementing enhanced security measures.
Leak gap clock⏱ Leak >30d13 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by safepay about this victim predates this filing by 61 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3a39e248d268e386Indiana State AGfiled 2025-07-10Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-10-mountain-laurel-dermatology-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2025
- Raw hash
- acba9a91317990854edc154b16de5e4d84b74f2d991c67ec3b32e6d5024b9425
Reporting entity
- Name
- Mountain Laurel Dermatologynorm: mountain laurel dermatology
- Domain
- mlderm.com
Victim entity
- Name
- Mountain Laurel Dermatologynorm: mountain laurel dermatology
- Domain
- mlderm.com
Incident
- Discovered
- Jun 27, 2025
- Materiality determined
- —
- Notification sent
- Jul 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 days(13 days from discovery to filing)
- Compliance flags
- Leak >30dVT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.