HackingHealthcareHealthcareStolen CredentialsCapture App DataCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIILowContained
Ellis Medicine
bd_fbd9cdca777dc587 · schema v1 · pii pii-v1
Full breach record for Ellis Medicine →Ellis Medicine, a healthcare organization in Schenectady, NY, identified suspicious activity related to an employee email account. An unauthorized person accessed the account during two periods: January 17–24, 2025 and March 27–April 5, 2025. The review was completed May 14, 2025. Personal information (names and other data elements) of 13,383 individuals, including 8 Maine residents, was potentially at risk. Credit monitoring services via TransUnion/Cyberscout were offered.
Maine clockDiscovered May 14, 2025 → Filed with AG Jul 22, 202569d ⏱ ME AG >30d10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_857dcf594b69322bVermont State AGfiled 2025-07-22Verified
- bd_c92ff11a81b2e709Indiana State AGfiled 2025-07-17(5d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/197ee9ca-ba55-4d1a-8633-97bd45c86cc4.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2025
- Raw hash
- 41e5d45d6b4f1c682a04313e1621aed7d2a7e682608fa4e6fcaca3f295e91890
Reporting entity
- Name
- Ellis Medicinenorm: ellis medicine
- Domain
- ellismedicine.org
- Industry
- Healthcare
Victim entity
- Name
- Ellis Medicinenorm: ellis medicine
- Domain
- ellismedicine.org
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- May 14, 2025
- Materiality determined
- —
- Notification sent
- Jul 17, 2025
- Affected individuals
- 8
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- ME AG >30d · 69dME resident >60d · 64d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 14, 2025→ Filed with AG: Jul 22, 202569d 30 days (soft) ME AG >30d Maine Discovered: May 14, 2025→ Notified: Jul 17, 202564d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.