Reid and Riege, P.C.
ent_0ca000a6178be82c2a53d889
Disclosures
4
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
610
nationwide · HHS OCR CT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Reid and Riege, P.C.
- Normalized
- reid and riege— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- CONNECTICUTHHS OCRas victim2022-09-28
Reid and Riege, P.C., a business associate (law firm) based in CT, reported to HHS on 2022-09-28 a ransomware incident affecting 610 individuals. Breached PHI was located on a Network Server and included names, addresses, dates of birth, diagnoses, medications, and other treatment information. The BA notified HHS and the media; the covered entity provided individual notification. In response, the BA implemented additional administrative and technical safeguards and retrained staff.
- Maine State AGas victim2022-09-26
Reid and Riege, P.C., a professional services firm, reported an external system breach that occurred on March 21, 2022, and was discovered on July 26, 2022. The incident affected 408 individuals, compromising names and financial account information. The firm began notifying affected individuals in writing on September 26, 2022, and offered 12 months of credit monitoring and identity restoration services through Experian.
- Massachusetts State AGas victim2022-06-03
Reid and Riege, P.C. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-06-03. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-06-03
Reid and Riege, P.C., a law firm, experienced a ransomware attack on March 21, 2022, discovered on May 20, 2022. The breach affected 46 individuals, including one resident of Maine. The compromised information included names and financial account numbers or credit/debit card numbers with their access codes. The firm provided written notification to the affected individuals on June 3, 2022, and offered 12 months of credit monitoring and identity restoration services through Experian.