Authentic Recovery Center reported a data breach to the Montana Attorney General. The breach was reported on 2018-08-15. The breach occurred from 6/7/2018 to 6/21/2018. 2 Montana residents were affected.
Affected (this filing): 2
Clustered 3 filings across 2 jurisdictions · filing window Aug 15, 2018 → Aug 17, 2018. View entity profile → Other incidents for this victim →
incident inc_bdf9e7da15e54c9d · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
CA MT
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Jun 7, 2018
When the intrusion reportedly occurred, per the linked filings
Jun 21, 2018
Reported by CALIFORNIA AG filing
Authentic Recovery Center reported a data breach to the Montana Attorney General. The breach was reported on 2018-08-15. The breach occurred from 6/7/2018 to 6/21/2018. 2 Montana residents were affected.
Affected (this filing): 2
Authentic Recovery Center, LLC reported to HHS on 2018-08-17 a Hacking/IT Incident affecting 1790 individuals. Breached information located on Email. A hacker gained unauthorized access to a workforce member’s email account via a phishing email. The email account contained the protected health information (PHI) of 1,790 individuals and included demographic, financial, and clinical information.
Affected (this filing): 1,790
Authentic Recovery Center, LLC reported a data breach affecting California residents. An unauthorized third party gained access to a secure email account between June 7, 2018, and June 21, 2018. Exposed data included names, client status, limited clinical information, driver's license numbers, and payment card information. No Social Security numbers were exposed. The company notified authorities, terminated access, and offered 12 months of identity theft protection.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.