Med-data incorporated
bd_01572e11b991a8d2 · schema v1 · pii pii-v1
Full breach record for Med-data incorporated →Med-Data, a revenue cycle services provider for healthcare systems, disclosed a security incident where a former employee saved files containing PHI (including SSNs, DOBs, and medical data) to a public website between Dec 2018 and Sep 2019. The incident was discovered on Dec 10, 2020, after a journalist alerted the company. 12 New Hampshire residents were affected. Med-Data engaged forensic specialists, removed the data, notified law enforcement and HHS, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 1, 2018
Begins
Dec 10, 2020
Discovered
Apr 8, 2021
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- HHS OCRbd_14e81bc1118830f02021-04-01 · +7dVerified
- Hawaii State AGbd_073059a1d70c76a32021-03-31 · +8dCandidate
- Indiana State AGbd_92cf2578eac8ebec2021-03-31 · +8dVerified
- Montana State AGbd_d90333e30b1f3be62021-03-31 · +8dVerified
Show 4 more filings ↓Show fewer ↑up to 99d gap
- Massachusetts State AGbd_9d43a830832396952021-04-26 · +18dVerified
- California State AGbd_d2fbe94657d113f02021-04-26 · +18dVerified
- Oregon State AGbd_28ea87358d1eeb422021-05-05 · +27dVerified
- Maine State AGbd_52a39a7ea123b7a32021-07-16 · +99dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Mar 31 (HI), last Jul 16 (ME) — a 107-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.