HackingPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Summit Behavioral Healthcare, Inc.
bd_f5dc2a1e453a2a38 · schema v1 · pii pii-v1
Full breach record for Summit Behavioral Healthcare, Inc. →Summit Behavioral Healthcare reported an unauthorized access to email systems occurring on May 12, 2020, discovered on January 21, 2021. The breach affected 70,822 individuals, exposing names and driver's license numbers. The company notified affected individuals in writing on February 26, 2021, and offered identity theft protection services. The incident was reported to the Maine Attorney General.
Maine clockDiscovered Jan 21, 2021 → Filed with AG Feb 26, 202136d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5b0678d99e52b7fdHHS OCRfiled 2021-02-26Verified
- bd_7c71a2b22d0e2df3California State AGfiled 2021-02-26Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/08078a33-fd8b-4398-ad0a-dfd024267f0d.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2021
- Raw hash
- 6ab235562f86a7ed84b634068a7de145e6536ccdaebc356880522ad00bf81de2
Reporting entity
- Name
- Summit Behavioral Healthcare, Inc.norm: summit behavioral healthcare
Victim entity
- Name
- Summit Behavioral Healthcare, Inc.norm: summit behavioral healthcare
Incident
- Discovered
- Jan 21, 2021
- Materiality determined
- —
- Notification sent
- Feb 26, 2021
- Affected individuals
- 70,822
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- ME AG >30d · 36d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 21, 2021→ Filed with AG: Feb 26, 202136d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.