BreachCensus

Berkeley Research Group, LLC

private companyHealthcareUnited States of America

Berkeley Research Group, LLC is a healthcare organisation in Vermont. It appears on the HHS OCR breach portal, the Massachusetts Attorney General breach-notification register, the California Attorney General breach-notification register, the Washington State Attorney General breach-notification register, the Texas Attorney General breach-notification register and the Vermont Attorney General breach-notification register with 4 confirmed incidents; the most recent notice was filed on August 31, 2026.

Data as of September 6, 2026.

Confirmed incident

US-VT

Disclosed
August 31, 2026

Timeline

  1. August 31, 2026
    Reported to regulator Regulator

    VT AG breach notification: 1,314 Vermont residents affected

    source
What a Vermont notice means

Required under 9 V.S.A. §2435. Notification to the Attorney General is required.

Note: the count is Vermont residents.

Vermont breach-notification register ↗

Confirmed incident

Filed in TX, CA, DE and WA — Ransomware Attack

The same incident was filed separately with 4 jurisdictions within a few days of each other (TX, CA, DE and WA) — shown here as one incident.

Occurred
February 28, 2025
Disclosed
November 4, 2025
Records affected
6,083

Timeline

  1. October 30, 2025
    Reported to regulator Regulator

    CA AG breach notification: an unknown number of California residents affected

    source
  2. October 30, 2025
    Reported to regulator Regulator

    WA AG breach notification: 17,188 Washington residents affected

    source
  3. October 30, 2025
    Reported to regulator Regulator

    DE AG breach notification: 0 Delaware residents affected

    source
  4. November 4, 2025
    Reported to regulator Regulator

    TX AG breach notification: 99 Texas residents affected

    source
  5. August 31, 2026
    Reported to regulator Regulator

    CA AG breach notification: an unknown number of California residents affected

    source
  6. September 1, 2026
    Reported to regulator Regulator

    TX AG breach notification: 92,290 Texas residents affected

    source
What a Texas notice means

Required under Tex. Bus. & Com. Code §521.053. Notice to the Attorney General is required when a breach affects at least 250 Texas residents.

Note: the published count is a total, not limited to Texas residents.

Texas breach-notification register ↗

What a California notice means

Required under Cal. Civ. Code §1798.82. A copy of the notification must be sent to the Attorney General when a single breach requires notifying more than 500 California residents.

Note: no affected-count is published on this register.

California breach-notification register ↗

What a Washington notice means

Required under RCW 19.255.010. Notice to the Attorney General is required when a breach affects more than 500 Washington residents.

Note: the count is Washington residents only, not a total.

Washington breach-notification register ↗

Confirmed incident

US-MA

Disclosed
October 30, 2025

Timeline

  1. October 30, 2025
    Reported to regulator Regulator

    MA AG breach notification: 5 Massachusetts residents affected

    source
What a Massachusetts notice means

Required under M.G.L. c. 93H. Notice to the Attorney General is required for a breach affecting any number of Massachusetts residents' personal information -- the statute sets no minimum count.

Note: the count is Massachusetts residents only, not a total.

Massachusetts breach-notification register ↗

Confirmed incident

US-CA — Hacking/IT Incident

Disclosed
April 30, 2025
Records affected
500

Reported with a business associate involved (HHS portal)

Timeline

  1. April 30, 2025
    Reported to regulator Regulator

    HHS OCR breach portal listing: Hacking/IT Incident; Network Server

    source