Confirmed breach. Intrusion Jul 5, 2024, discovered Jul 5, 2024 — the first regulatory filing landed 237 days later (flagged late). 21 individuals reported across the linked filings.
Service Access & Management, Inc. notified the Maryland AG of a data security incident discovered on July 5, 2024. An unauthorized user accessed systems, affecting 17 Maryland residents with names, SSNs, and medical information. SAM engaged forensic specialists, reset credentials, rebuilt systems, and offered 12 months of credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Service Access & Management, Inc. (SAM), a nonprofit human services organization in Pennsylvania and New Jersey, discovered suspicious activity on its network on July 5, 2024. An unauthorized user potentially accessed SAM's systems. By September 12, 2024, affected files were identified; a review completed January 31, 2025 confirmed some PII may have been exposed. Four Maine residents were affected. Notifications were sent February 27, 2025. IDX credit monitoring was offered.
Affected (this filing): 4
ME AG >90d · 237dME resident >180d · 237d
🍁Vermont State AGlinked via multistate filing link · 100%
Service Access & Management, Inc. (SAM), a nonprofit human services provider, notified consumers of a data security incident discovered on July 5, 2024. An unauthorized user potentially accessed SAM's systems, impacting names and variable data elements. SAM engaged forensic experts, reset passwords, notified law enforcement, and offered credit monitoring via IDX. No evidence of misuse was found at the time of notification.