Clustered 6 filings across 6 jurisdictions · filing window Jun 20, 2025 → Jun 30, 2025. View entity profile → Other incidents for this victim →
incident inc_a5c8faafc793495d · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Identity (basic) · Government ID
IN ME MI NH TX VT
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Jul 17, 2024 → Aug 3, 2024
When the intrusion reportedly occurred, per the linked filings
Aug 5, 2024
Reported by VERMONT AG, NEW HAMPSHIRE AG, MAINE AG filings
May 5, 2025
Reported by TEXAS AG filing
McLaren Health Care reported to HHS on 2025-06-24 a Hacking/IT Incident affecting 743131 individuals. Breached information located on Network Server.
Affected (this filing): 743,131
McLaren Health Care based in Grand Blanc, Michigan, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-05-05 and reported on 2025-06-30. 841 Texas residents were affected. 743,131 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail;Broadcast on Texas-wide Media.
Affected (this filing): 841
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
McLaren Health Care notified Vermont AG of a ransomware attack impacting patient networks between July 17 and August 3, 2024. The attack targeted McLaren and Karmanos systems. Data potentially exposed includes names and government identifiers. McLaren engaged forensic investigators, secured the network, and is offering identity theft protection services to affected individuals.
McLaren Health Care notified the NH AG of a ransomware attack. Unauthorized access occurred July 17–Aug 3, 2024. Discovered Aug 5, 2024. Affected 15 NH residents with PII, SSN, driver's license, and PHI. Notification sent June 20, 2025. Credit monitoring offered.
Affected (this filing): 15
McLaren Health Care reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-17 and was reported on 2025-06-20. 530 Indiana residents were affected. 743,131 individuals affected in total.
Affected (this filing): 743,131
McLaren Health Care, a healthcare organization, reported an external system breach (hacking) that affected 743,131 individuals, including 25 Maine residents. The breach occurred on July 17, 2024, and was discovered on August 5, 2024. Notification to affected Maine residents was sent on June 20, 2025. The company is offering 12 months of identity protection services through IDX.
Affected (this filing): 25