Harbor
ent_8541b79adfb7b2d8764b59cb
Disclosures
11
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
216,000
nationwide · HHS OCR OH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Harbor
- Normalized
- harbor— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500C7FE073838RB48
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- goharbor.io
Disclosure history (11)newest first
- Nebraska State AGas victim2025-10-24
Harbor, a healthcare entity, notified Nebraska residents of a data breach involving unauthorized access to its network between July 25 and August 1, 2025. Suspicious activity was detected on August 1, 2025. Affected data includes names, SSNs, driver's licenses, medical/clinical info, and financial account data. Harbor provided credit monitoring via Epiq and notified regulators, including HHS.
- Massachusetts State AGas victim2025-10-24
Harbor reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-10-24. 10 Massachusetts residents were affected.
- Maine State AGas victim2025-10-24
Harbor, a healthcare entity, reported an external system breach (hacking) affecting 5 Maine residents. Unauthorized access occurred between July 25 and August 1, 2025. Compromised data included names, SSNs, driver's licenses, medical/financial info. Harbor notified HHS, credit bureaus, and affected individuals, offering 12 months of credit monitoring via Epiq. Investigation is ongoing.
- New Hampshire State AGas victim2025-10-24
Harbor, a healthcare provider in Toledo, OH, notified the NH AG of a data event affecting 3 NH residents. Unauthorized access occurred July 25–Aug 1, 2025; detected Aug 1, 2025. Data included PII (SSN, DL), PHI, and financial info. Notices sent Sept 30, 2025. Investigation ongoing.
- Vermont State AGas victim2025-10-24
Harbor notified consumers of a data breach where an unauthorized actor accessed and exfiltrated files between July 25 and August 1, 2025. The incident involved patients, employees, and board members. Compromised data included names, SSNs, driver's licenses, medical diagnoses, and financial account information. Harbor engaged in investigation, notified affected individuals via mail and website, and offered credit monitoring services.
- Montana State AGas victim2025-10-24
Harbor notified patients, employees, and board members of unauthorized access to its network between July 25 and August 1, 2025. The incident involved the exfiltration of PII (SSN, DL), PHI, and financial data. Harbor launched an investigation, sent notices via mail and website, and offered credit monitoring. No specific count of affected individuals was provided in this Montana filing.
- Illinois State AGas victim2025-10-01
HARBOR filed a data-breach notice with the Illinois Attorney General in October 2025 (case 25-10-545). The register records the breach as discovered on August 1, 2025. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OHIOHHS OCRas victim2025-09-30
HHS OCR Breach Portal entry: Harbor (Ohio, Healthcare Provider) reported a Hacking/IT Incident affecting a Network Server on 2025-09-30. 216,000 individuals affected. No business associate involvement reported. No further narrative provided in the portal row.
- OHIOHHS OCRas victim2025-06-20
Harbor reported to HHS on 2025-06-20 a Hacking/IT Incident affecting 2703 individuals. Breached information located on Email.
- Massachusetts State AGas victim2019-05-18
Harbor reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-05-18. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- OHIOHHS OCRas victim2019-04-12
Harbor reported to HHS on 2019-04-12 a Hacking/IT Incident affecting 29,972 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing ePHI including names, addresses, SSNs, and medical data. Harbor implemented safeguards and retrained staff.