Confirmed breach. Intrusion Jul 25, 2025–Aug 1, 2025, discovered Aug 1, 2025 — the first regulatory filing landed 60 days later (flagged late). 216,014 individuals reported across the linked filings.
HHS OCR Breach Portal entry: Harbor (Ohio, Healthcare Provider) reported a Hacking/IT Incident affecting a Network Server on 2025-09-30. 216,000 individuals affected. No business associate involvement reported. No further narrative provided in the portal row.
Affected (this filing): 216,000
HHS notified
Most recent
4 State AG filingsOct 24, 2025ExpandCollapse
MENHVTMT
🦞Maine State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Harbor experienced an external system breach (hacking) that was discovered on August 1, 2025. The breach occurred on July 25, 2025, and affected 5 Maine residents. Affected individuals were offered 12 months of credit monitoring and identity theft protection services.
Affected (this filing): 5
ME AG >30d · 84dME resident >60d · 84d
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Harbor, a healthcare provider in Toledo, OH, notified the NH AG of a data event affecting 3 NH residents. Unauthorized access occurred July 25–Aug 1, 2025; detected Aug 1, 2025. Data included PII (SSN, DL), PHI, and financial info. Notices sent Sept 30, 2025. Investigation ongoing.
Affected (this filing): 3
🍁Vermont State AGlinked via same-victim cross-source · 95%
Harbor notified consumers of a data breach where an unauthorized actor accessed and exfiltrated files between July 25 and August 1, 2025. The incident involved patients, employees, and board members. Compromised data included names, SSNs, driver's licenses, medical diagnoses, and financial account information. Harbor engaged in investigation, notified affected individuals via mail and website, and offered credit monitoring services.
VT AG >45 bday
🦬Montana State AGlinked via same-victim cross-source · 95%
Harbor reported a data breach to the Montana Attorney General. The breach was reported on 2025-10-24. The breach occurred from 07/25/2025 to 08/01/2025. 6 Montana residents were affected.