Confirmed breach. Intrusion Sep 18, 2025–Sep 19, 2025, discovered Sep 18, 2025 — the first regulatory filing landed 195 days later (flagged late). 61 individuals reported across the linked filings.
IPPC, a long-term care pharmacy, notified Delaware AG of unauthorized access to its network between Sept 18-19, 2025. An unknown actor copied files containing patient identity and government ID data. IPPC took systems offline, engaged law enforcement, and offers 12 months of credit monitoring. The investigation was completed in Feb 2026.
IPPC Inc., a long-term care pharmacy, notified Vermont residents of a data breach occurring between September 18-19, 2025. An unknown actor accessed the network and copied files containing names, Social Security numbers, and medical/health insurance information. 61 Vermont residents were notified. IPPC took systems offline, engaged law enforcement, notified HHS, and provided credit monitoring guidance.
Affected (this filing): 61
VT AG >45 bday
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.