Confirmed breach. Intrusion Mar 1, 2021, discovered Mar 5, 2021 — the first regulatory filing landed 60 days later. 330,143 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksMaine⏱ ME AG >30d · 60dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Orthopedic Associates of Dutchess County reported to HHS on 2021-05-04 a Hacking/IT Incident affecting 330,143 individuals. Breached information located on Network Server. The incident involved a ransomware attack encrypting PHI including names, SSNs, and treatment info. Response included FBI notification and credit monitoring.
Affected (this filing): 330,143
HHS notified
🦞Maine State AGMost recentlinked via same-victim cross-source · 100%
Orthopedic Associates of Dutchess County, a healthcare organization, reported an external system breach (hacking) that occurred on March 1, 2021, and was discovered on March 5, 2021. The breach affected 91 Maine residents. The compromised information included names or other personal identifiers in combination with financial account numbers or credit/debit card numbers along with their security codes, access codes, passwords, or PINs. The organization provided written notification to the affected individuals on May 4, 2021, and offered 12 months of identity and credit monitoring services through Experian.
Affected (this filing): 91
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.