AccidentalHealthcareHealthcareMisconfigurationCustomer Data InvolvedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Inmediata Health Group
bd_07367e77ebb86296 · schema v1 · pii pii-v1
Full breach record for Inmediata Health Group →In January 2019, Inmediata Health Group Corp. discovered that electronic patient health information was publicly accessible online due to a webpage setting that allowed search engines to index pages of an internal website. Data potentially exposed included names, addresses, dates of birth, gender, medical claim information, and in some cases Social Security numbers. The company deactivated the website, engaged a computer forensics firm, and sent notifications in April 2019. No evidence of data misuse or file copying was found.
California clockDiscovered Jan 1, 2019 → Notified Apr 22, 2019111d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_a3280d85edb47707Montana State AGfiled 2019-04-30Candidate
- bd_6002e6858d8b16caOregon State AGfiled 2019-06-03(34d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-146769
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 30, 2019
- Raw hash
- df4830c97cc65de4f3c90270631c10a4920747bcf4df6819ce8bb7f87eec0b91
Reporting entity
- Name
- Inmediata Health Groupnorm: inmediata health
Victim entity
- Name
- Inmediata Health Groupnorm: inmediata health
- Industry
- Healthcarellm
Incident
- Discovered
- Jan 1, 2019
- Materiality determined
- —
- Notification sent
- Apr 22, 2019
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- CA 60-day late · 111d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 1, 2019→ Notified: Apr 22, 2019111d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.