Cottage Hospital reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-14 and was reported on 2026-02-06. 8 Indiana residents were affected. 2,156 individuals affected in total.
Affected (this filing): 2,156
Clustered 4 filings across 3 jurisdictions · filed Feb 6, 2026. View entity profile → Other incidents for this victim →
incident inc_e37c2cd643f94af1 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
IN NH VT
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Oct 14, 2025
When the intrusion reportedly occurred, per the linked filings
Dec 8, 2025
Reported by VERMONT AG, NEW HAMPSHIRE AG filings
Cottage Hospital reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-14 and was reported on 2026-02-06. 8 Indiana residents were affected. 2,156 individuals affected in total.
Affected (this filing): 2,156
Cottage Hospital notified consumers of a data breach where unauthorized access occurred between Oct 14-21, 2025. Compromised data included names, SSNs, driver's licenses, bank account info, and PHI. The hospital engaged third-party experts, offered credit monitoring, and enhanced security measures.
Cottage Hospital reported to HHS on 2026-02-06 a Hacking/IT Incident affecting 37796 individuals. Breached information located on Network Server.
Affected (this filing): 37,796
Cottage Hospital notified the NH Attorney General of a breach affecting 1,138 NH residents. Unauthorized access occurred Oct 14-21, 2025; discovered Dec 8, 2025. Exposed data includes names, SSNs, driver's licenses, and bank account info. Notifications mailed Feb 6, 2026. Remediation includes credit monitoring and enhanced security measures.
Affected (this filing): 1,138
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.