Confirmed breach. Intrusion Apr 3, 2023–Apr 10, 2023, discovered Apr 3, 2023 — the first regulatory filing landed 344 days later (flagged late). 85,640 individuals reported across the linked filings.
Regulatory clocksWashington✗ WA AG >90dCalifornia✗ CA 60-day late · 344dHIPAA✓ HHS notifiedMaine✓ ME AG ≤30d · 30dFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforced
Affected (total reported)
85,640
Data types
24days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
—
Jurisdictions
5
CA FEDERAL ME MT WA
Linked filings
6
HHS OCR · State AG
Affected residents by state
per-filing reported counts
WA1,273
MT34
ME4
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Apr 3, 2023 → Apr 10, 2023
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Apr 3, 2023
Reported by CALIFORNIA AG filings
Breach discoveredconflicts with Apr 3, 2023AG web form
CCM Health, a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-04-10 and filed notice on 2024-03-12. 1,273 Washington residents were affected. 337 days elapsed between awareness and notification. 7 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 1,273
WA AG >90d
🐻California State AGlinked via same-victim cross-source · 100%
CCM Health notified the California Attorney General of a network security incident where an unauthorized party accessed its network between April 3 and April 10, 2023. The organization became aware of the potential unauthorized access on April 3, 2023. A forensic investigation concluded that files containing personal and health information, including Social Security Numbers, were accessed and removed. CCM Health contained the threat, engaged third-party cybersecurity professionals, and alerted law enforcement. Affected individuals are offered 12 months of complimentary credit monitoring.
CA 60-day late · 344d
🇺🇸FEDERALHHS OCRlinked via same-victim cross-source · 100%
CCM Health reported to HHS on 2024-03-12 a Hacking/IT Incident affecting 84329 individuals. Breached information located on Network Server.
Affected (this filing): 84,329
HHS notified
Most recent
3 State AG filingsMar 12, 2024 – Apr 5, 2024ExpandCollapse
MTMECA
🦬Montana State AGlinked via multistate filing link · 100%
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
CCM Health reported a data breach to the Montana Attorney General. The breach was reported on 2024-03-12. The breach occurred from 4/3/2023 to 4/10/2023. 34 Montana residents were affected.
Affected (this filing): 34
🦞Maine State AGlinked via operator-confirmed · 100%
CCM Health, a healthcare organization, reported an external system breach that occurred from April 3, 2023, to April 10, 2023. The breach was discovered on February 12, 2024, and affected 4 Maine residents. The compromised data included names and Social Security numbers. The company offered 12 months of credit monitoring and identity restoration services through Cyberscout.
Affected (this filing): 4
ME AG ≤30d · 30d
🐻California State AGlinked via operator-confirmed · 100%
CCM Health notified California residents of a network security incident where unauthorized access occurred between April 3 and April 10, 2023. The attacker may have accessed and removed files containing personal information (name, date of birth) and protected health information (medical records, diagnoses, treatments). CCM Health contained the threat, engaged forensic investigators, and alerted law enforcement. No specific malware or threat actor was named.