Confirmed breach. Intrusion May 14, 2024, discovered May 1, 2024 — the first regulatory filing landed 387 days later. 57,412 individuals reported across the linked filings.
The Cooper Health System notified the NH Attorney General of a data security incident discovered in May 2024. Unauthorized actors may have acquired personal and protected health information. One NH resident was notified. Cooper engaged cybersecurity experts and is offering credit monitoring.
Affected (this filing): 1
🏎️Indiana State AGlinked via same-victim cross-source · 100%
The Cooper Health System reported a data breach to the Indiana Attorney General. The breach occurred on 2024-05-14 and was reported on 2025-05-23. 2 Indiana residents were affected. 57,412 individuals affected in total.
Affected (this filing): 57,412
🇺🇸NJHHS OCRlinked via same-victim cross-source · 100%
The Cooper Health System reported to HHS on 2025-05-23 a Hacking/IT Incident affecting 57412 individuals. Breached information located on Network Server.
Affected (this filing): 57,412
HHS notified
🦞Maine State AGMost recentlinked via same-victim cross-source · 100%
The Cooper Health System, a healthcare organization headquartered in Camden, NJ, experienced an external system breach (hacking) in May 2024 involving unauthorized access to its network. The breach was discovered on March 26, 2025, after a thorough investigation with cybersecurity experts. Affected data included names and Social Security numbers of 57,412 individuals total, with 1 Maine resident affected. Notifications were sent May 23, 2025. IDX identity protection services were offered.
Affected (this filing): 1
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.