Welcome to Carolina Arthritis Since its founding in 1991, Carolina Arthritis has been leading the way in the diagnosis and treatment of arthritis, musculoskeletal disorders, connective tissue diseases, autoimmune illnesses and osteoporosis. At...
Clustered 7 filings across 7 jurisdictions · filing window Oct 24, 2024 → Feb 27, 2025. View entity profile → Other incidents for this victim →
incident inc_bcc698f22ccd440f · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
PII · PHI · Government ID
IN MD ME NC NH VT
Leak Site · HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Sep 27, 2024
When the intrusion reportedly occurred, per the linked filings
Sep 27, 2024
Reported by NEW HAMPSHIRE AG, MARYLAND AG, VERMONT AG filings
Welcome to Carolina Arthritis Since its founding in 1991, Carolina Arthritis has been leading the way in the diagnosis and treatment of arthritis, musculoskeletal disorders, connective tissue diseases, autoimmune illnesses and osteoporosis. At...
Jan 21, 2025
Reported by MAINE AG filing
Carolina Arthritis Associates, a rheumatology practice, notified the NH AG of a data security incident on Feb 27, 2025. Unauthorized access occurred on Sept 27, 2024, affecting personal information of 4 NH residents. The company engaged cybersecurity experts and offered identity protection services.
On September 27, 2024, Carolina Arthritis Associates, a rheumatology practice in Wilmington, NC, experienced a computer network disruption. Cybersecurity experts determined that certain files may have been acquired without authorization. The breach was discovered on January 21, 2025. Affected data for 3 Maine residents (36,961 total) may include name, date of birth, medical treatment/procedure information, medical record number, medical provider name, and Social Security number.
Carolina Arthritis Associates reported to HHS on 2025-02-27 a Hacking/IT Incident affecting 36,961 individuals. Breached information located on Network Server. The incident involved protected health information (PHI) including clinical, demographic, and financial data. The entity provided credit monitoring, implemented security safeguards, and retrained staff.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Affected (this filing): 4
Affected (this filing): 3
Affected (this filing): 36,961
Carolina Arthritis Associates notified Vermont AG of a data security incident on Sept 27, 2024, involving unauthorized acquisition of files containing patient names. The organization engaged forensic experts, reported to the FBI, and provided 12 months of credit monitoring and identity protection services to affected individuals.
Carolina Arthritis Association reported a data breach to the Indiana Attorney General. The breach occurred on 2024-09-27 and was reported on 2025-02-27. 7 Indiana residents were affected. 36,961 individuals affected in total.
Affected (this filing): 36,961
Carolina Arthritis Associates reported a data security incident occurring on September 27, 2024, involving unauthorized access to files containing personal information. The breach affected Maryland residents, with data types including names and government identifiers (SSN/driver's license). The company engaged forensic investigators, reported the incident to the FBI, and mailed notifications offering 12 months of credit monitoring and identity protection services via CyberScout.