Confirmed breach. Intrusion Dec 26, 2024–Dec 30, 2024, discovered Dec 30, 2024 — the first regulatory filing landed 210 days later (flagged late). 8 individuals reported across the linked filings.
Central New York Cardiology notified consumers of a data breach occurring between Dec 26-30, 2024. Unauthorized access to network activity resulted in the acquisition of names and variable data elements. No evidence of misuse was found. The provider offered 12-24 months of credit monitoring and identity protection services.
VT AG >45 bday
⛰️New Hampshire State AGMost recentlinked via multistate filing link · 100%
Central New York Cardiology notified New Hampshire AG of a breach affecting 8 NH residents. Unauthorized access occurred Dec 26-30, 2024. Data included names, DOB, SSN, and medical info. CNYC engaged forensic specialists, secured systems, notified law enforcement, and offered credit monitoring. Notices sent July 25, 2025.
Affected (this filing): 8
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.