Confirmed breach. Intrusion Feb 28, 2023–Mar 13, 2023, discovered Mar 13, 2023 — the first regulatory filing landed 109 days later (flagged late). 587,459 individuals reported across the linked filings.
Regulatory clocksWashington✗ WA AG >90dOregon✗ OR AG >45dMaine✗ ME AG >90d · 129dCalifornia✗ CA 60-day late · 80dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforced
Affected (total reported)
587,459
Data types
52days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
—
Jurisdictions
5
CA ME NH OR WA
Linked filings
13
HHS OCR · State AG
Affected residents by state
per-filing reported counts
OR461,100
ME152,818
OR118,965
WA6,376
NH770
ME221
ME27
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
13 filings across 5 jurisdictions · Jun 30, 2023 – Aug 21, 2023 · 2 milestones
Breach window
Mar 7, 2023
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Mar 13, 2023
Reported by WASHINGTON AG, OREGON AG, NEW HAMPSHIRE AG, MAINE AG, CALIFORNIA AG filings
109 days
🦫Oregon State AGFirst filinglinked via same-victim cross-source · 100%
Orrick, Herrington & Sutcliffe LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-30. The breach occurred during 3/7/2023 - 3/7/2023. The breach was discovered on 3/13/2023. 118,965 individuals were affected. Notice was sent on 6/30/2023.
Affected (this filing): 118,965
🌲Washington State AGlinked via multistate filing link · 95%
Orrick, Herrington & Sutcliffe LLP, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-03-13 and filed notice on 2023-06-30. 6,376 Washington residents were affected. 109 days elapsed between awareness and notification. 6 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 6,376
WA AG >90d
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Orrick, Herrington & Sutcliffe LLP reported to HHS on 2023-06-30 a Hacking/IT Incident affecting 342,176 individuals. Breached information located on Network Server. The business associate experienced a cyber-attack compromising PHI including names, diagnoses, SSNs, and insurance info. Response included credit monitoring and enhanced safeguards.
Affected (this filing): 342,176
Most recent
10 State AG filingsJun 30, 2023 – Aug 21, 2023ExpandCollapse
CANHMEOR
California State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Orrick, Herrington & Sutcliffe LLP notified the California AG of a security event impacting data obtained during its representation of a vision benefits plan manager. The incident, dated March 7, 2023, exposed names, addresses, dates of birth, and Social Security numbers. The firm offered free identity monitoring services to affected individuals.
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Orrick, Herrington & Sutcliffe, LLP notified the NH Attorney General of a security incident detected on March 13, 2023. An unauthorized third party gained remote access to a file share, obtaining personal information of clients' customers between Feb 28 and Mar 13, 2023. 770 NH residents affected. Orrick engaged forensic experts, notified law enforcement, and offered 2 years of credit monitoring via Kroll.
Affected (this filing): 770
🦞Maine State AGlinked via multistate filing link · 100%
Orrick, Herrington & Sutcliffe LLP reported an external system breach (hacking) occurring on 02/28/2023 and discovered on 03/13/2023. The incident affected 152,818 individuals, including 1 Maine resident. Personal information acquired included names and Social Security Numbers. The firm provided written notification and offered 24 months of complimentary identity monitoring services through Kroll.
Affected (this filing): 152,818
ME AG >90d · 129dME resident >60d · 129d
🦞Maine State AGlinked via multistate filing link · 95%
Legal services firm Orrick, Herrington & Sutcliffe LLP reported a data breach affecting 152,818 individuals, including 27 Maine residents. The breach, described as an external system breach (hacking), occurred on March 7, 2023, and was discovered on March 13, 2023. The compromised information includes names and Social Security numbers. The firm began notifying affected individuals on July 21, 2023, and offered two years of identity monitoring services through Kroll.
Affected (this filing): 27
ME AG >90d · 129dME resident >60d · 130d
🐻California State AGlinked via multistate filing link · 95%
Orrick, Herrington & Sutcliffe LLP notified the California AG of a security event on March 7, 2023, affecting individuals enrolled in a vision benefits plan for which Orrick served as legal counsel. Affected data included name, address, date of birth, and Social Security numbers. Orrick offered free identity monitoring services.
🐻California State AGlinked via multistate filing link · 95%
Orrick, Herrington & Sutcliffe LLP reported a data breach to the California Attorney General. The incident occurred on March 7, 2023. The firm offered identity monitoring services to affected individuals. The specific nature of the breach and data types are not detailed in the provided summary page, though PII is implied by the offer of identity monitoring.
🐻California State AGlinked via multistate filing link · 95%
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick is a downstream service provider for MultiPlan, Inc. The firm engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring through Kroll.
CA 60-day late · 80d
🦫Oregon State AGlinked via multistate filing link · 95%
Orrick, Herrington & Sutcliffe LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-18. The breach occurred during 2/28/2023 - 3/13/2023. The breach was discovered on 3/13/2023. 461,100 individuals were affected. Notice was sent on 6/30/20237/20/20238/18/2023.
Affected (this filing): 461,100
OR AG >45d
🦞Maine State AGlinked via multistate filing link · 95%
Law firm Orrick, Herrington & Sutcliffe LLP reported a data breach impacting 461,100 individuals, including 221 Maine residents. The breach occurred on February 28, 2023, and was discovered on March 13, 2023. The incident was categorized as an external system breach (hacking), where threat actors acquired names combined with driver's license or non-driver identification card numbers. The firm provided written notification to affected individuals on July 20, 2023, and August 18, 2023, and offered two years of Kroll identity monitoring services.
Affected (this filing): 221
ME AG >90d · 158dME resident >60d · 129d
🐻California State AGlinked via multistate filing link · 100%
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. The incident involved personal information of plan participants, including health insurance data (PHI), stored in connection with Orrick's representation of MultiPlan, Inc. Orrick blocked access, engaged forensic experts, notified law enforcement, and is offering two years of identity monitoring.