Confirmed breach. Intrusion Jan 1, 2016–Dec 31, 2017, discovered Aug 24, 2021 — the first regulatory filing landed 71 days later. 19,396 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksMaine⏱ ME AG >30d · 71dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
19,396
Data types
2
Government ID · Identity (basic)
Jurisdictions
2
ME NJ
Linked filings
2
HHS OCR · State AG
Sensitive data
identity_government
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Jan 1, 2016 → Dec 31, 2017
When the intrusion reportedly occurred, per the linked filings
University Hospital reported an insider wrongdoing incident occurring between 01/01/2016 and 12/31/2017, discovered on 08/24/2021. The breach compromised names and Social Security Numbers of 9,329 individuals, including 2 Maine residents. Notification was sent on 10/08/2021, offering one year of credit monitoring via Experian.
Affected (this filing): 9,329
ME AG >30d · 71d
🇺🇸NJHHS OCRMost recentlinked via same-victim cross-source · 100%
University Hospital (NJ) reported to HHS on 2021-11-05 an Unauthorized Access/Disclosure affecting 10,067 individuals. A workforce member impermissibly accessed PHI including names, addresses, dates of birth, SSNs, health insurance information, diagnoses, and other treatment information stored in Electronic Medical Records. The CE sanctioned the responsible workforce member and retrained staff.
Affected (this filing): 10,067
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.