Confirmed breach. Intrusion May 12, 2020–May 20, 2020, discovered Jan 21, 2021 — the first regulatory filing landed 36 days later. 70,822 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksMaine⏱ ME AG >30d · 36dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
70,822
Data types
4
PHI · Health (basic) · Identity (basic)
Jurisdictions
3
CA ME TN
Linked filings
3
HHS OCR · State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
May 12, 2020 → May 20, 2020
When the intrusion reportedly occurred, per the linked filings
254 days
Breach discovered
Jan 21, 2021
Reported by MAINE AG filing
36 days
🇺🇸TNHHS OCRFirst filinglinked via same-victim cross-source · 100%
Summit Behavioral Healthcare reported to HHS on 2021-02-26 a Unauthorized Access/Disclosure affecting 70,822 individuals. Breached information located on Email. An employee impermissibly emailed ePHI to a personal account. The entity implemented additional administrative, technical, and security safeguards.
Affected (this filing): 70,822
🐻California State AGlinked via same-victim cross-source · 100%
Summit Behavioral Healthcare (SBHC) experienced unauthorized access to two employee email accounts between approximately May 12–20, 2020. Suspicious activity was detected in late May 2020, but the investigation did not confirm that protected health information (PHI) was affected until January 21, 2021. A third-party forensics firm conducted the investigation. Affected individuals were notified in February 2021 and offered 12 months of free credit and identity monitoring through IDX.
🦞Maine State AGMost recentlinked via same-victim cross-source · 100%
Summit Behavioral Healthcare reported an unauthorized access to email systems occurring on May 12, 2020, discovered on January 21, 2021. The breach affected 70,822 individuals, exposing names and driver's license numbers. The company notified affected individuals in writing on February 26, 2021, and offered identity theft protection services. The incident was reported to the Maine Attorney General.
Affected (this filing): 70,822
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.