Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Gastro Health Holdco, LLC
bd_f89b870182b31cd2 · schema v1 · pii pii-v1
Full breach record for Gastro Health Holdco, LLC →Gastro Health disclosed a phishing incident on February 25, 2026, resulting in unauthorized access to patient files. Affected data included names, SSNs, DOBs, state IDs, medical record numbers, and financial account numbers. The incident is contained, with no indication of fraud. Gastro Health provided 24 months of credit monitoring via Epiq Privacy Solutions.
Massachusetts clock⏱ MA AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_47955d57ccbe42f7Indiana State AGfiled 2026-05-22(21d gap)Verified
- bd_b3e6b30ae05db95fHHS OCRfiled 2026-05-22(21d gap)Verified
- bd_c5c7efc4ddd11f45HHS OCRfiled 2026-05-22(21d gap)Verified
- bd_d2f4d6ae22071958New Hampshire State AGfiled 2026-05-22(21d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 21d gap
- bd_fa70a8cc2319eb4eWashington State AGfiled 2026-05-22(21d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-835-gastro-health/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- d0ac00b0b22764d2a4ca34577c778af0f8ac8f0fda76868420320ea63b02dd1b
Reporting entity
- Name
- Gastro Health Holdco, LLCnorm: gastro health holdco
Victim entity
- Name
- Gastro Health Holdco, LLCnorm: gastro health holdco
Incident
- Discovered
- Feb 25, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.