MalwareHealthcareHealthcareRansomwareCapture Stored DataData EncryptedData ExfiltratedRansom DemandedCustomer Data InvolvedDelayed DiscoveryPIIPHILowContained
Highlands Oncology Group PA
bd_f3067e691ab1bd55 · schema v1 · pii pii-v1
Full breach record for Highlands Oncology Group PA →Highlands Oncology Group PA, a healthcare provider based in Springdale, AR, discovered on June 2, 2025 that it had been the victim of a cyber-attack in which an unauthorized third party accessed its network between January 21, 2025 and June 2, 2025, encrypting files and potentially exfiltrating personal and health information. Total affected individuals: 113,575 nationwide; 6 Maine residents. Experian IdentityWorks Credit 3B (12 months) offered to affected individuals.
Maine clockDiscovered Jun 2, 2025 → Filed with AG Aug 1, 202560d ⏱ ME AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2e1c0c273573a6f2HHS OCRfiled 2025-08-01Verified
- bd_dbb625888ec67b01New Hampshire State AGfiled 2025-08-01Verified
- bd_2ae199a4db46ef0eTexas State AGfiled 2025-08-04(3d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/762ba0e7-40a5-4a0f-a838-29772fc01be2.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2025
- Raw hash
- 9279cf3a423a5b5a1120241d772e0f38a04126a1c85cc963312ec3968ecdf091
Reporting entity
- Name
- Highlands Oncology Group PAnorm: highlands oncology
- Industry
- Healthcare
Victim entity
- Name
- Highlands Oncology Group PAnorm: highlands oncology
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Jun 2, 2025
- Materiality determined
- —
- Notification sent
- Aug 1, 2025
- Affected individuals
- 6
- Data types
- PIIPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- ME AG >30d · 60d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 2, 2025→ Filed with AG: Aug 1, 202560d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.