Confirmed breach. Intrusion Oct 25, 2023–Oct 26, 2023, discovered Oct 25, 2023 — the first regulatory filing landed 181 days later (flagged late). 26,601 individuals reported across the linked filings.
Advarra, Inc, a third-party service provider for Moffitt Cancer Center, notified consumers of a data breach occurring on October 25, 2023. An unauthorized third party accessed a single employee account, compromising names. Advarra disabled the account, engaged cybersecurity experts, and provided 24 months of free identity monitoring via Kroll. The incident is contained.
🦞Maine State AGlinked via same-victim cross-source · 100%
Moffitt Cancer Center and Research Institute reported a data breach impacting 24 Maine residents after a third-party vendor experienced a security incident. The breach occurred between October 25, 2023, and October 26, 2023, and was discovered on February 21, 2024. The compromised information includes names and Social Security Numbers. Affected individuals were notified on April 23, 2024, and offered 24 months of credit monitoring and identity theft protection services through Kroll.
Affected (this filing): 24
ME AG >30d · 63d
🇺🇸FLHHS OCRMost recentlinked via same-victim cross-source · 100%
Moffitt Cancer Center and Research Institute (FL) reported to HHS on 2024-04-24 a Hacking/IT Incident affecting 26,577 individuals. The covered entity's business associate experienced a cybersecurity incident that exposed PHI including names, Social Security numbers, dates of birth, claims information, diagnoses, and medications. Breached information located on Network Server. The CE and BA provided credit monitoring; the BA implemented additional administrative, technical, and security safeguards.
Affected (this filing): 26,577
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.