Ellis Medicine
bd_fbd9cdca777dc587 · schema v1 · pii pii-v1
Full breach record for Ellis Medicine →Ellis Medicine, a healthcare provider, notified 13,383 individuals (including 8 Maine residents) of a phishing incident involving unauthorized access to an employee email account. The breach occurred between January 17, 2025, and April 5, 2025, and was discovered on May 14, 2025. Ellis Medicine reset passwords, enabled MFA, engaged third-party investigators, and provided 12 months of credit monitoring services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 17, 2025
Begins
May 14, 2025
Discovered
Jul 22, 2025
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_857dcf594b69322b2025-07-22Verified
- Massachusetts State AGbd_9c599feaafa2b2182025-07-22Verified
- Nebraska State AGbd_2afdc743245a36aa2025-07-17 · +5dVerified
- Indiana State AGbd_c92ff11a81b2e7092025-07-17 · +5dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 17 (NE), last Jul 22 (ME) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.