Inmediata Health Group
bd_07367e77ebb86296 · schema v1 · pii pii-v1
Full breach record for Inmediata Health Group →Inmediata Health Group, Corp. disclosed that in January 2019, patient health information was publicly available online due to a webpage setting that permitted search engines to index internal business operation pages. The exposed data included names, addresses, dates of birth, gender, and medical claim information (diagnosis/procedure codes). For some individuals, Social Security numbers were also exposed. The company deactivated the website, engaged forensic investigators, and removed indexed data from search engines. No evidence of data copying or misuse was found.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 22, 2019
Begins
Apr 30, 2019
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_a3280d85edb477072019-04-30Candidate
- HHS OCRbd_f12cfc9ad29648572019-05-07 · +7dVerified by operator
- Oregon State AGbd_6002e6858d8b16ca2019-06-03 · +34dVerified
- HHS OCR enforcementbd_b591e1e63f897fff2024-12-10 · +2051dVerified by operator
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Apr 30 (MT), last Dec 10 — a 2051-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.