Confirmed breach. Intrusion Oct 2, 2024, discovered Oct 1, 2024 — the first regulatory filing landed 202 days later (flagged late). 357,265 individuals reported across the linked filings.
Onsite Mammography, LLC notified consumers of a data security incident discovered in October 2024 involving unauthorized access to an employee's email account. The incident exposed patients' names and specific health-related information (PHI). The company engaged independent cybersecurity experts and a data analytics vendor to investigate and assess the scope.
VT AG >45 bday
🏛️MASSACHUSETTSHHS OCRlinked via same-victim cross-source · 100%
Onsite Mammography reported to HHS on 2025-04-21 a Hacking/IT Incident affecting 357265 individuals. Breached information located on Email. Business Associate present: Yes.
Affected (this filing): 357,265
HHS notified
Most recent
3 State AG filingsApr 21, 2025ExpandCollapse
INNHME
🏎️Indiana State AGlinked via same-victim cross-source · 100%
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Onsite Mammography reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-02 and was reported on 2025-04-21. 6,529 Indiana residents were affected. 357,265 individuals affected in total.
Affected (this filing): 357,265
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Onsite Mammography, LLC notified the New Hampshire Attorney General of a data security incident affecting approximately 39 New Hampshire residents. The incident involved unauthorized access to an employee's email account in October 2024, likely via phishing. The actor accessed email content potentially containing PII and PHI. Onsite engaged cybersecurity experts, reset passwords, notified law enforcement, and is offering credit monitoring services.
Affected (this filing): 39
🦞Maine State AGlinked via same-victim cross-source · 100%
In October 2024, an unauthorized actor gained access to a single employee email account at Onsite Mammography LLC, a national healthcare imaging services provider. The intrusion was discovered on April 15, 2025 following a data analytics vendor review concluding February 21, 2025. PHI and PII of patients may have been exposed. The actor did not access other systems. 357,265 individuals were affected nationally; 32 Maine residents. Equifax credit monitoring (12 months) was offered.