Country : United States of America - Exfiltraded data : yes - Encrypted data : yes
Clustered 4 filings across 4 jurisdictions · filing window Mar 19, 2024 → Oct 31, 2024. View entity profile → Other incidents for this victim →
incident inc_8a62593744904023 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
MT OR WA
Leak Site · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Feb 26, 2024
When the intrusion reportedly occurred, per the linked filings
Feb 26, 2024
Reported by WASHINGTON AG filing
Country : United States of America - Exfiltraded data : yes - Encrypted data : yes
May 6, 2024
Reported by OREGON AG filing
Therapeutic Health Services, a non-profit/charity sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2024-02-26 and filed notice on 2024-07-11. 24,281 Washington residents were affected. 136 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
Therapeutic Health Services reported a data breach to the Montana Attorney General. The breach was reported on 2024-07-18. The breach occurred on 2/26/2024. 61 Montana residents were affected.
Affected (this filing): 61
Therapeutic Health Services reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-31. The breach occurred during 2/24/2024 - 2/26/2024. The breach was discovered on 5/6/2024. 27,170 individuals were affected. Notice was sent on 7/18/202410/17/202410/29/2024.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Affected (this filing): 24,281
Affected (this filing): 27,170