Confirmed breach. Intrusion Mar 2, 2021–Mar 5, 2021, discovered Mar 5, 2021 — the first regulatory filing landed 196 days later. 62,930 individuals reported across the linked filings.
Horizon House, Inc. notified Delaware AG of a data event occurring between March 2-5, 2021. Suspicious activity led to the potential viewing or taking of personal information (name, government IDs) by an unknown actor. The company notified federal law enforcement, offered credit monitoring via TransUnion, and is reviewing security policies.
🇺🇸PAHHS OCRlinked via same-victim cross-source · 100%
Horizon House, Inc. (PA) reported to HHS OCR on 2021-09-17 a Hacking/IT Incident (ransomware attack) affecting 27,823 individuals. Breached information was located on a Network Server. Compromised PHI included names, dates of birth, driver's license numbers, addresses, Social Security numbers, claims and financial information, diagnoses, and other treatment information. The entity notified HHS, individuals, and media, and implemented additional administrative, technical, and security safeguards. OCR provided technical assistance on the HIPAA Security Rule.
Affected (this filing): 27,823
🦞Maine State AGMost recentlinked via operator-confirmed · 100%
Horizon House, Inc., a healthcare entity based in Philadelphia, PA, reported an external system breach (hacking) occurring between March 2 and March 5, 2021. The incident compromised the personal information (names and financial account or credit/debit card numbers) of 35,107 individuals, including one Maine resident. The breach was discovered on September 3, 2021, and written notifications were sent to affected individuals on September 17, 2021, offering 12 months of credit monitoring services.
Affected (this filing): 35,107
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.