Shields Health Care Group, Inc.
ent_f7a84e03e518b835cc841c8b
Disclosures
17
State AG · HHS OCR · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
2,380,483
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Shields Health Care Group, Inc.
- Normalized
- shields health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- shields.com
Disclosure history (17)newest first
- New Hampshire State AGas victim2023-04-24
Shields Health Care Group, Inc. issued a supplemental notice to the New Hampshire Attorney General regarding a data security incident. An unknown actor gained unauthorized access to Shields systems between March 7 and March 21, 2022. The breach impacted approximately 9,789 New Hampshire residents, exposing personal information including Social Security numbers. Shields notified law enforcement, engaged forensic specialists, rebuilt systems, and provided 24 months of credit monitoring through Kroll to affected individuals.
- Maine State AGas victim2023-04-19
Shields Health Care Group, Inc. reported an external system breach affecting 2,260 Maine residents. The breach occurred between March 7, 2022, and March 28, 2022, and was discovered on March 28, 2022. The compromised data includes names combined with driver's license or non-driver identification card numbers. The company began notifying affected individuals on July 25, 2022, with further notifications on April 19, 2023. Shields Health Care Group offered two years of credit monitoring and identity theft protection services through Kroll.
- Vermont State AGas victim2023-04-19
Shields Health Care Group, Inc. notified consumers of a data security incident where an unknown actor accessed systems between March 7 and March 21, 2022. The breach potentially exposed personal information including names and government identifiers. Shields engaged forensic specialists, notified law enforcement, rebuilt systems, and offered 24 months of identity monitoring through Kroll.
- California State AGas victim2023-04-19
Shields Health Care Group, Inc. reported that an unknown actor gained unauthorized access to certain systems from March 7, 2022, to March 21, 2022. The company was alerted to suspicious activity on March 28, 2022. The investigation revealed that certain data was acquired by the actor. Shields provides management and imaging services for health care facilities. Affected data may include personal and health information. Shields activated incident response protocols, notified law enforcement, engaged third-party forensics, rebuilt systems, and offered 24 months of identity monitoring through Kroll.
- Illinois State AGas victim2023-01-01
SHIELDS HEALTH CARE GROUP, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-268). The register records the breach as discovered on March 7, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2022-07-26
Shields Health Care Group, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a data breach affecting approximately 8,181 NH residents. An unknown actor accessed systems between March 7 and March 21, 2022. Data compromised included SSNs, PHI, and patient identifiers. Shields engaged forensic specialists, notified law enforcement, rebuilt systems, and offered 24 months of credit monitoring. The investigation was ongoing at the time of filing.
- Indiana State AGas victim2022-07-25
Shields Health Care Group, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-03-07 and was reported on 2022-07-25. 65 Indiana residents were affected. 1,804,069 individuals affected in total.
- Washington State AGas victim2022-07-22
Shields Health Care Group, Inc. disclosed a cyberattack where an unknown actor gained unauthorized access to systems from March 7-21, 2022, acquiring data including SSNs and PHI. Discovered March 28, 2022. Notifications sent July 25, 2022, to ~1,018 individuals (586 in WA). Response included law enforcement notification, forensic investigation, system rebuilding, and 2-year credit monitoring via Kroll.
- California State AGas victim2022-07-22
Shields Health Care Group, Inc. notified the California AG of a data security incident where an unknown external actor gained unauthorized access to systems from March 7-21, 2022. The company was alerted to suspicious activity on March 28, 2022. The investigation confirmed data was acquired by the actor. Shields provides management and imaging services for healthcare facilities. Affected data may include PHI and PII. Shields engaged forensics, notified law enforcement, rebuilt systems, and offered 24 months of identity monitoring via Kroll.
- Maine State AGas victim2022-07-22
Shields Health Care Group, Inc. reported a data breach to the Maine Attorney General's office, indicating that an external system breach (hacking) occurred between March 7, 2022, and March 28, 2022. The breach was discovered on March 28, 2022, and affected 1,695 Maine residents. The compromised information includes names and Social Security numbers. Shields Health Care Group offered two years of credit monitoring and identity theft protection services through Kroll to the affected individuals.
- Montana State AGas victim2022-07-22
Shields Health Care Group, Inc. notified individuals of a security incident where an unknown actor accessed systems from March 7-21, 2022. Data compromised included names, SSNs, DOBs, addresses, and PHI. Shields engaged forensic specialists, notified law enforcement, rebuilt systems, and offered 24 months of credit monitoring.
- Oregon State AGas victim2022-07-22
Shields Health Care Group, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-07-22. The breach occurred during 3/7/2022 - 3/28/2022. The breach was discovered on 3/28/2022. 1,804,069 individuals were affected. Notice was sent on 7/22/2022.
- Massachusetts State AGas victim2022-06-14
Shields Health Care Group Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-06-14. 688,855 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2022-06-14
Shields Health Care Group, Inc. notified the NH AG of a data event where an unknown actor accessed systems from March 7-21, 2022. Discovered March 28, 2022. PHI and SSN compromised. Notification sent May 27, 2022. Investigation ongoing; count of affected individuals not yet determined.
- New Hampshire State AGas victim2022-06-14
Shields Health Care Group, Inc. notified the New Hampshire Attorney General on June 10, 2022, of a data event affecting New Hampshire residents. An unknown actor accessed Shields systems between March 7 and March 21, 2022. Shields became aware of suspicious activity on March 28, 2022. The incident involved the exfiltration of PHI and PII, including SSNs, names, and DOB. Substituted notice was provided on May 27, 2022. The investigation and data review remain ongoing.
- MASSACHUSETTSHHS OCRas victim2022-05-27
Shields Health Care Group, Inc. reported to HHS on 2022-05-27 a Hacking/IT Incident affecting 2,380,483 individuals. Breached information located on Network Server. The business associate reported that it was the subject of a data breach that affected the protected health information (PHI) of 2,380,483 individuals. The PHI involved included clinical, demographic, and financial information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional administrative, technical, and security safeguards.
- Illinois State AGas victim2022-01-01
SHIELDS HEALTH CARE GROUP filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-457). The register records the breach as discovered on March 28, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.