Burr & Forman LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-30 and was reported on 2024-01-09. 32 Indiana residents were affected. 28,616 individuals affected in total.
Affected (this filing): 28,616
Clustered 5 filings across 5 jurisdictions · filing window Jan 9, 2024 → Jan 10, 2024. View entity profile → Other incidents for this victim →
incident inc_6757b705d8e5438f · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
PHI · Identity (basic) · Government ID
FEDERAL IN ME MT VT
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Sep 30, 2023
When the intrusion reportedly occurred, per the linked filings
Oct 23, 2023
Reported by HHS OCR, MAINE AG, VERMONT AG filings
Burr & Forman LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-30 and was reported on 2024-01-09. 32 Indiana residents were affected. 28,616 individuals affected in total.
Affected (this filing): 28,616
Burr & Forman LLP, an Alabama-based law firm acting as a HIPAA business associate, reported a ransomware incident on 2024-01-09 affecting protected health information of 19,893 individuals. PHI involved included names, dates of birth, Social Security numbers, claims and financial information, and treatment information, stored on a network server. The firm notified HHS, affected individuals, and the media; posted substitute notice on its website; offered complimentary credit monitoring and identity protection services; and implemented additional technical safeguards.
Affected (this filing): 19,893
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Burr & Forman LLP, a law firm, reported a data breach to the Maine Attorney General, stating that an external system breach (hacking) occurred and was discovered on October 23, 2023. The breach affected 2 Maine residents and compromised their names and Social Security numbers. The company began notifying affected individuals on January 9, 2024, and offered identity theft protection services.
Affected (this filing): 2
Burr & Forman LLP notified consumers of a data security incident discovered on October 23, 2023, involving anomalous activity on a laptop. An unauthorized actor accessed documents containing names, SSNs, medical coding info, and insurance data. Burr & Forman engaged cybersecurity experts, notified the FBI, and offered 24 months of credit monitoring via IDX.
Burr & Forman LLP reported a data breach to the Montana Attorney General. The breach was reported on 2024-01-10. The breach occurred on 10/23/2023. 4 Montana residents were affected.
Affected (this filing): 4