Confirmed breach. Intrusion Jul 26, 2024–Jul 28, 2024, discovered Jul 28, 2024 — the first regulatory filing landed 138 days later (flagged late). 2,749 individuals reported across the linked filings.
Judge Baker Children's Center reported an unauthorized access incident occurring July 26-28, 2024, discovered July 28, 2024. An external actor accessed systems and potentially downloaded files containing PII of one NH resident. The Center engaged forensic experts, secured its environment, notified the FBI, and offered credit monitoring.
Affected (this filing): 1
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
The Baker Center for Children and Families reported a supplemental data security incident affecting 34 New Hampshire residents. Unauthorized access occurred July 26-28, 2024, discovered July 28. Personal information potentially impacted. FBI notified; credit monitoring offered.
Affected (this filing): 34
🏛️MASSACHUSETTSHHS OCRlinked via same-victim cross-source · 100%
Judge Baker Children's Center dba The Baker Center for Children and Families (MA) reported to HHS OCR on 2024-12-27 a Hacking/IT Incident (cyber-attack) affecting the PHI of 2,715 individuals. Breached information was located on a Network Server. PHI affected included names, birthdates, addresses, Social Security and driver's license numbers, and financial and treatment information — notably including pediatric records. The CE notified HHS, affected individuals, and the media, and provided complimentary credit monitoring while strengthening its administrative and technical safeguards.
Affected (this filing): 2,715
🍁Vermont State AGMost recentlinked via same-victim cross-source · 100%
Judge Baker Children’s Center (dba The Baker Center for Children and Families) notified Vermont AG of a data breach discovered July 28, 2024. Unauthorized access occurred July 26-28, 2024, potentially impacting names and PHI. The organization engaged forensic experts, notified the FBI, and offered 24 months of Experian IdentityWorks.
VT AG >45 bday
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.