Confirmed breach. Intrusion Mar 6, 2026–Mar 7, 2026, discovered Mar 7, 2026 — the first regulatory filing landed 46 days later (flagged late). 2,287 individuals reported across the linked filings.
Harbor Developmental Disabilities Foundation (d/b/a Harbor Regional Center) reported to HHS on 2026-04-22 a Hacking/IT Incident affecting 2287 individuals. Breached information located on Network Server. Business Associate present.
Affected (this filing): 2,287
🏎️Indiana State AGlinked via same-victim cross-source · 100%
Harbor Developmental Disabilities Foundation dba Harbor Regional Center reported a data breach to the Indiana Attorney General. The breach occurred on 2026-03-06 and was reported on 2026-04-22. 1 Indiana residents were affected. 1,157 individuals affected in total.
Affected (this filing): 1,157
🐻California State AGlinked via same-victim cross-source · 100%
Harbor Developmental Disabilities Foundation (d/b/a Harbor Regional Center) notified the California Attorney General of a data breach occurring on March 6-7, 2026. The organization became aware of unusual network activity on March 7, 2026. An investigation revealed that an unauthorized individual may have accessed certain personal information. The review of impacted data concluded on April 16, 2026. Affected individuals in multiple states, including California, are being offered 12 months of credit monitoring and fraud assistance services. No misuse of information has been detected at this time.
Harbor Developmental Disabilities Foundation (d/b/a Harbor Regional Center) notified individuals of a data breach occurring on March 6-7, 2026, discovered on March 7, 2026. An unauthorized individual accessed personal information, including names, addresses, SSNs, and health records. The organization engaged forensic investigators and is providing 12 months of credit monitoring and fraud assistance to affected individuals in multiple states.
Harbor Developmental Disabilities Foundation (d/b/a Harbor Regional Center) notified the California Attorney General of a data breach occurring on March 6-7, 2026. The organization became aware of unusual network activity on March 7, 2026. An investigation revealed that an unauthorized individual accessed certain personal information. The incident is contained. Affected individuals are offered 12 months of credit monitoring and fraud assistance services.
CA 30-day late · 128d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.