DisclosureLens
AccidentalHealthcareProfessional ServicesHealthcareMisconfigurationCustomer Data InvolvedData ExfiltratedIdentity (basic)Government IDHealth (basic)MediumContained

MedEvolve

bd_0bd4122eff0cddb4 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 11, 2018

Filed

Jul 10, 2018

To disclose

9 weeks

Affected

Not disclosed

Linked

8 filings

Confidence

64%
Full breach record for MedEvolve

MedEvolve, a provider of electronic billing and record services to physicians and medical facilities, discovered on May 11, 2018, that an FTP file containing patient information was inadvertently accessible to the internet from March 29, 2018, to May 4, 2018. The file was subject to unauthorized access on March 29, 2018. Affected data included names, billing addresses, telephone numbers, primary health insurer account numbers, and Social Security numbers. MedEvolve secured the portal, engaged forensic investigators, and offered two years of complimentary credit monitoring.

Incident timeline

undetected · 43 days
discovery → filing · 9 weeks / 60 days

Mar 29, 2018

Begins

May 11, 2018

Discovered

Jul 10, 2018

Filed

vs. sector median

4 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 1771d gap

Filing propagation · 8 filings · 5 states

View merged incident ↗
Massachusetts State AGJul 10 · first
HHS OCRJul 10 · first
New Hampshire State AGJul 10 · first
Montana State AGJul 10 · first
California State AGJul 10 · first · this page

Pattern: first filing Jul 10 (MA), last May 16 — a 1771-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.