Clustered 6 filings across 4 jurisdictions · filing window Jan 30, 2026 → May 20, 2026. View entity profile → Other incidents for this victim →
incident inc_1a6110e8e72d4592 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII · PHI
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA NH SC WA
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Jul 8, 2024 → Jul 9, 2024
When the intrusion reportedly occurred, per the linked filings
Jul 8, 2024
Reported by WASHINGTON AG filing
Jul 9, 2024
Reported by CALIFORNIA AG, NEW HAMPSHIRE AG, SOUTH CAROLINA AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The Phia Group, LLC notified California residents of a data security incident discovered on July 9, 2024. Unauthorized access occurred between July 8 and July 9, 2024, potentially exposing names and health-related information. The company engaged forensic specialists, secured systems, and offered credit monitoring services.
The Phia Group, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2024-07-08 and filed notice on 2026-01-30. 2,802 Washington residents were affected. 571 days elapsed between awareness and notification. 0 days to identify the breach. 1 days to contain the breach.
Affected (this filing): 2,802
The Phia Group, LLC, a healthcare cost containment provider, notified the New Hampshire Attorney General of a data security incident affecting 13 NH residents. Suspicious activity was detected on July 9, 2024, involving unauthorized access to personal information, including Social Security Numbers, between July 8-9, 2024. The company engaged forensic specialists, reported to law enforcement, and provided credit monitoring services to affected individuals. No evidence of fraudulent misuse was found.
Affected (this filing): 13
The Phia Group, LLC, a healthcare cost containment provider, issued a supplemental notice to the New Hampshire Attorney General regarding a July 2024 security incident. Suspicious activity disrupted network operability, and data was potentially acquired between July 8-9, 2024. The incident affected 1,433 New Hampshire residents, exposing SSNs, driver's license numbers, and financial account information. Phia engaged forensic specialists, reported to law enforcement, and provided credit monitoring via Kroll. Notifications to residents occurred between January and April 2026.
Affected (this filing): 1,433
The Phia Group, LLC experienced a data security incident involving ransomware that disrupted network operability. Suspicious activity was discovered on July 9, 2024, with data potentially acquired between July 8 and July 9, 2024. Affected data includes names and health-related information. The company engaged forensic specialists, secured the environment, and offered credit monitoring services.
The Phia Group, LLC notified South Carolina AG of a data security incident affecting approximately 3,470 individuals. Suspicious activity was discovered on July 9, 2024, involving unauthorized access to personal information (names) between July 8-9, 2024. The company engaged forensic specialists, reported to law enforcement, and provided 12 months of identity monitoring via Kroll.
Affected (this filing): 3,470