Clustered 4 filings across 4 jurisdictions · filed Mar 15, 2021. View entity profile → Other incidents for this victim →
incident inc_eefe4daa0c604ecf · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ME MT OR
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Jun 1, 2020 → Nov 15, 2020
When the intrusion reportedly occurred, per the linked filings
Nov 29, 2020
Reported by CALIFORNIA AG filing
Jan 15, 2021
Reported by MAINE AG, OREGON AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Quality CPR Care LLC (dba American CPR Care Association) experienced an external system breach between June 1 and November 15, 2020, discovered on January 15, 2021. The incident affected 13,689 individuals, including 41 Maine residents. The breach involved the unauthorized acquisition of names and financial account or credit/debit card numbers (including security codes/PINs). The entity notified consumers in writing on March 15, 2021, but did not offer identity theft protection services.
Affected (this filing): 13,689
Quality CPR Care LLC dba American CPR Care Association reported a data breach to the Oregon Attorney General. The breach was reported on 2021-03-15. The breach occurred during 6/1/2020 - 11/15/2020. The breach was discovered on 1/15/2021. 13,689 individuals were affected. Notice was sent on 3/15/2021.
Affected (this filing): 13,689
Quality CPR Care LLC (dba American CPR Care Association) disclosed a data breach in California involving unauthorized access to its payment card environment via a webshell. The incident, discovered on November 29, 2020, potentially exposed customer names and debit/credit card numbers stored temporarily for quality assurance. The company engaged forensic investigators, reset passwords, and enhanced policies to stop storing payment card data.
American CPR Care Association (Quality CPR Care LLC) reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-15. The breach occurred from 11/29/2020 to 12/16/2020. 48 Montana residents were affected.
Affected (this filing): 48