McDermott Will & Schulte LLP
ent_019e209ef4ec55c8697be3e33abfefa6
Disclosures
12
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
6
incidents joining 2+ filings here
Max affected reported
2,500,000
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- McDermott Will & Schulte LLP
- Normalized
- mcdermott will schulte— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300UMG3O2LATV4G18
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mcdermottlaw.com
Disclosure history (12)newest first
- Vermont State AGas victim2026-08-28
McDermott Will & Schulte LLP reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-08-28. The reporting organization type is Other Commercial. 15 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- Indiana State AGas victim2026-08-28
McDermott Will & Schulte LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2026-05-07 and was reported on 2026-08-28. 63 Indiana residents were affected. 10,905 individuals affected in total.
- ILLINOISHHS OCRas victim2026-08-26
McDermott Will & Schulte LLP reported to HHS on 2026-08-26 a Unauthorized Access/Disclosure affecting 5427 individuals. Breached information located on Network Server.
- Massachusetts State AGas victim2026-08-01
On May 7, 2026, McDermott Will & Schulte LLP inadvertently provided copies of a limited number of documents containing personal information to an unauthorized person. The firm launched an investigation with third-party experts and notified law enforcement. Affected individuals may have had name and government ID data (passports, driver's licenses) exposed. The firm is offering two years of identity monitoring via Kroll and assistance with passport and driver's license replacements.
- New Hampshire State AGas reporting2026-02-11
TriZetto Provider Solutions (TPS) notified the New Hampshire Attorney General of a security incident involving unauthorized access to a web portal used by healthcare providers. TPS became aware of suspicious activity on October 2, 2025, and determined that an unauthorized actor accessed historical eligibility transaction reports containing PHI and PII (names, SSNs, DOB) starting November 2024. TPS engaged Mandiant, contained the threat, and notified approximately 1,795 New Hampshire residents. Remediation included portal security review and offering 12 months of credit monitoring.
- Maine State AGas reporting2025-02-11
Ciox Health LLC d/b/a Datavant Group reported a phishing incident affecting 49,454 individuals. Unauthorized access occurred May 8-9, 2024, via compromised email accounts. Data exposed included names, SSNs, financial accounts, driver's licenses, and health information. Datavant engaged forensic experts, implemented security safeguards, and offered 24 months of Kroll identity monitoring.
- Idaho State AGas reporting2024-11-15
athenahealth, Inc. notified the Idaho Attorney General on November 15, 2024, of a cybersecurity incident affecting one Idaho resident. The incident involved the inadvertent upload of Eligibility Transaction Files to a publicly accessible internet repository due to a manual configuration error by an employee. The files contained demographic and clinical data (names, addresses, DOB, provider info) but no financial or SSN data. athenahealth removed the files, investigated, and provided 12 months of Experian IdentityWorks to the affected individual.
- Massachusetts State AGas reporting2024-10-07
McDermott Will & Emery LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-10-07. 2 Massachusetts residents were affected.
- Maine State AGas reporting2023-12-08
Norton Healthcare, Inc. reported an external system breach (hacking) occurring between May 7 and May 9, 2023. The incident affected approximately 2,500,000 individuals, including 385 Maine residents. Acquired data included names combined with driver's license numbers. Norton Healthcare notified affected individuals in writing on December 8, 2023, and provided 24 months of credit monitoring and identity theft protection through Kroll.
- New Hampshire State AGas reporting2018-08-27
Sierra Nevada Brewing Co. notified the New Hampshire Attorney General of a security event involving its e-commerce platform (sierranevadagiftshop.com). Magento, the platform provider, identified a vulnerability allowing an unauthorized person to install malicious code to monitor form entries. The incident potentially affected 4 New Hampshire residents, exposing names, addresses, emails, credit card numbers, CVV2s, and usernames/passwords. Sierra Nevada took the site offline, engaged forensic counsel, and sent notices to affected residents on August 28, 2018, offering one year of identity protection.
- ILLINOISHHS OCRas reporting2015-03-24
McDermott Will & Emery LLP reported to HHS on 2015-03-24 a Hacking/IT Incident affecting 880 individuals. Breached information located on Network Server. Business associate Blue Cross and Blue Shield of Illinois (parent: Anthem, Inc.) experienced cyberattacks exposing ePHI including names, SSNs, and medical IDs.
- New Hampshire State AGas reporting2015-02-27
McDermott Will & Emery LLP notified the NH AG of a cyber-attack on Anthem, Inc., a downstream subcontractor for its health plan. Attack commenced ~Dec 10, 2014, discovered Jan 29, 2015. PHI, PII, and SSNs potentially exposed. Investigation ongoing; specific impact on NH residents undetermined.
Supply-chain cascadesreviewed and confirmed
- McDermott Will & Schulte LLP’s filing is one of at least 12 in the ANTHEM INSURANCE COMPANIES, INC. supply-chain incident (2015).