HackingData ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)Downstream VictimsTargetedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumActive
Medical Informatics Engineering
bd_09ef90b2209ecb87 · schema v1 · pii pii-v1
Full breach record for Medical Informatics Engineering →Medical Informatics Engineering (MIE) and its subsidiary NoMoreClipboard reported a sophisticated cyber attack. Unauthorized access occurred May 7-8, 2015, and was detected May 26, 2015. Protected health information (PHI), including names, addresses, DOBs, SSNs, and medical conditions, was exposed. MIE engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring. Investigation was ongoing at time of filing.
California clockDiscovered May 26, 2015 → Notified Jun 2, 20157d ✓ CA 60-day OK4 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56609
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2015
- Raw hash
- f2b29b8e95cf510d2c668239c0af7340f68645e766383c602e9b7e071f93fcd8
Reporting entity
- Name
- Medical Informatics Engineeringnorm: medical informatics engineering
- Domain
- mieweb.org
Victim entity
- Name
- Medical Informatics Engineeringnorm: medical informatics engineering
- Domain
- mieweb.org
Incident
- Discovered
- May 26, 2015
- Materiality determined
- —
- Notification sent
- Jun 2, 2015
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported incident to FBI Cyber SquadNotifying HHSNotifying applicable State Attorneys GeneralNotifying national consumer reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 7d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 26, 2015→ Notified: Jun 2, 20157d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.