DisclosureLens
HHS OCRState AGConfirmed3 filings · 3 statesLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Merged incident · 3 filings

Samaritan Healthcare & Hospice — May 2020 breach

Clustered 3 filings across 3 jurisdictions · filing window Sep 3, 2020 Sep 14, 2020. View entity profile → Other incidents for this victim →

1 cross-filing discrepancyMerge100%

Determination

Confirmed

Members

3 filings

States

3

Affected · reported

3,657

First → last filing

Sep 3, 2020 Sep 14, 2020

Merge confidence

100%

incident inc_4655f0e418ae4a25 · merged by deterministic · confidence 100%

Part of the BLACKBAUD, INC. supply-chain incident (2020)at least 172 organizations filed notifications naming this third party.
Confirmed breach. One breach, 3 legal records. Intrusion May 1, 2020–May 20, 2020, discovered Aug 6, 2020 — the first regulatory filing landed 28 days later. 3,657 individuals reported across the linked filings. Notifications rolled out on a 11-day schedule across 3 filings beginning Sep 3, 2020. This page is the deduped roll-up; each member filing remains the legal record for its jurisdiction.

Litigation Timing

Supplemental
Notification delay
28days

Discovered → first regulatory filing

Filing span
11days

Time between earliest and latest filing

Not recorded for this incident

Discovery variance · Leak precedence · Materiality delta · SEC filing delayno leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.

Regulatory clocksHIPAA HHS notifiedFull clock table in Litigation Timeline

Sensitive data

identity_government

Incident timeline

May 1, 2020breach begins
Aug 6, 2020discovered
notification delay · 28 days
Sep 3, 2020first filing
Sep 14, 2020most recent filing

Dashed segments are unestablished, not zero — they fill in as filings merge into this incident.

Member cascade — every filing about this breach

  1. SEP 3MA AGMA AG noticefirst filing · 1 MA residentsday 0
  2. SEP 8NH AGNH AG notice1 NH residents+5d
  3. SEP 14HHS OCRHHS OCR noticemost recent · states nationwide total 3,657+11d
  4. Watching for additional filings — new sources merge into this incident automatically.

Roll-up facts — reconciled across members

Breach window
May 1, 2020May 20, 2020
NH AG
Discovered
Aug 6, 2020· 97d undetected
NH AG
Data types
Identity (basic) · Government ID
MA AG + NH AG + HHS OCR
Attack vector
Third-Party / Supply Chain
NH AG
Response
Working diligently to gather additional information from Blackbaud to understand the scope of the incident · Reviewing its existing policies and procedures regarding third-party vendors · Working with Blackbaud to confirm the use of additional measures and safeguards to protect against this type of incident in the future
NH AG

Each fact cites the member filing that establishes it; when filings conflict, every value shows with its source.

Count reconciliation

per-state reported counts

Nationwide (stated in a filing)

3,657

Sum of filed state slices

2· 0.1% of stated

100% of the stated total lives in states whose filings carry no count — the dashed share shrinks as filings land.

Evidence ladder — rungs this incident occupies

Leak-site claim

No leak-site claim on record for this incident.

Press / market report

No press coverage linked yet.

State AG / regulator filing3 members

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

No SEC filing or victim statement yet.

Merge provenance

Method
deterministic
Confidence
1.00 · above the 0.85 auto-merge floor
Audit
Every link edge records its method, confidence and model + prompt versions (100% is the strongest edge).

Merges are reversible — a wrong link can be detached with its audit trail intact. How merging works.

Filing velocity

Spread

11 days

Cadence

~1 / 5.5d

vs. multi-state median

2.2× slower

About this clustering

DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.