Confirmed breach. Intrusion Jan 15, 2026, discovered Jan 31, 2026 — the first regulatory filing landed 40 days later. 2,507,080 individuals reported across the linked filings.
Nacogdoches Memorial Hospital reported a data breach to the Indiana Attorney General. The breach occurred on 2026-01-31 and was reported on 2026-03-12. 57 Indiana residents were affected. 257,073 individuals affected in total.
Affected (this filing): 257,073
⭐TEXASHHS OCRlinked via same-victim cross-source · 100%
Nacogdoches Memorial Hospital, a Texas healthcare provider, reported a Hacking/IT Incident to HHS OCR affecting protected health information on a network server. The breach report submitted on March 30, 2026 indicates approximately 2,507,073 individuals were affected. No business associate was reported to be involved.
Affected (this filing): 2,507,073
HHS notified
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Nacogdoches Memorial Hospital reported a cybersecurity incident to the New Hampshire Attorney General on March 31, 2026. The hospital became aware of the unauthorized access to its network on January 31, 2026. The breach potentially exposed patient information, including names, addresses, SSNs, dates of birth, and medical records. Two New Hampshire residents were notified. The hospital engaged law enforcement, reset credentials, and enhanced network security.
Affected (this filing): 2
🦞Maine State AGMost recentlinked via multistate filing link · 95%
Nacogdoches Memorial Hospital (Nacogdoches, TX) reported an external system breach (hacking) occurring on January 15, 2026, discovered January 31, 2026. A total of 257,073 individuals were affected nationally; 5 Maine residents were affected. Consumer notification was sent March 31, 2026. The filing describes a HIPAA patient notice. No identity theft protection services were offered.
Affected (this filing): 5
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.