Confirmed breach. Intrusion Apr 14, 2025–Apr 15, 2025, discovered Apr 15, 2025 — the first regulatory filing landed 100 days later (flagged late). 58,839 individuals reported across the linked filings.
McKenzie Memorial Hospital notified consumers of a data breach occurring between April 14-15, 2025. Unauthorized access may have resulted in the exposure of names. The hospital engaged third-party investigators, notified law enforcement, and is offering 12 months of credit monitoring. The incident status is contained.
🦞Maine State AGlinked via same-victim cross-source · 100%
McKenzie Memorial Hospital reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on April 14, 2025. The breach was discovered on June 19, 2025, and affected 6 Maine residents. The hospital provided written notification to affected individuals on July 24, 2025, and offered 12 months of credit monitoring and identity theft protection services through TransUnion.
Affected (this filing): 6
ME AG >30d · 35d
🇺🇸MIHHS OCRlinked via same-victim cross-source · 100%
McKenzie Memorial Hospital reported to HHS on 2025-07-24 a Hacking/IT Incident affecting 58839 individuals. Breached information located on Network Server.
Affected (this filing): 58,839
HHS notified
⛰️New Hampshire State AGMost recentlinked via same-victim cross-source · 100%
McKenzie Memorial Hospital notified the NH AG of a data incident where an unauthorized actor accessed files between April 14-15, 2025. The breach affected 2 NH residents, exposing names, SSNs, and financial account info. The hospital engaged law enforcement and forensic specialists, secured the network, and offered 12 months of credit monitoring.
Affected (this filing): 2
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.