Confirmed breach. Intrusion Sep 18, 2025–Sep 19, 2025, discovered Sep 19, 2025 — the first regulatory filing landed 60 days later (flagged late). 518 individuals reported across the linked filings.
Dermatology Associates of Concord (MA) reported to HHS OCR on 2025-11-18 a Hacking/IT Incident affecting 501 individuals. Breached information was located on a Network Server. No business associate was identified. No further details were provided in the HHS web description.
Affected (this filing): 501
HHS notified
🍁Vermont State AGlinked via same-victim cross-source · 100%
Dermatology Associates of Concord notified consumers of a cyber-attack where an unauthorized actor accessed a specific system and copied files containing names between Sept 18-19, 2025. The incident was discovered on Sept 19, 2025. No evidence of fraud was found. The organization engaged third-party cybersecurity experts, notified law enforcement, enhanced security protocols, and is offering 24 months of credit monitoring services.
VT AG >45 bday
⛰️New Hampshire State AGMost recentlinked via same-victim cross-source · 100%
Dermatology Associates of Concord (DAC) notified the New Hampshire Attorney General of a data event affecting 17 NH residents. Unauthorized access occurred between Sept 18-19, 2025, involving copying of files containing names, SSNs, driver's licenses, passports, and medical info. DAC engaged third-party cybersecurity experts, notified law enforcement, and provided 2 years of TransUnion credit monitoring. Investigation is ongoing.
Affected (this filing): 17
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.