MedEvolve
bd_0bd4122eff0cddb4 · schema v1 · pii pii-v1
Full breach record for MedEvolve →MedEvolve, a provider of electronic billing and record services to physicians and medical facilities, discovered on May 11, 2018, that an FTP file containing patient information was inadvertently accessible to the internet from March 29, 2018, to May 4, 2018. The file was subject to unauthorized access on March 29, 2018. Affected data included names, billing addresses, telephone numbers, primary health insurer account numbers, and Social Security numbers. MedEvolve secured the portal, engaged forensic investigators, and offered two years of complimentary credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 29, 2018
Begins
May 11, 2018
Discovered
Jul 10, 2018
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Massachusetts State AGbd_2cc6cf8c3756184a2018-07-10Verified
- HHS OCRbd_6ac38550f52fc8d32018-07-10Verified
- New Hampshire State AGbd_a0496aa58a430ab52018-07-10Verified
- Montana State AGbd_a2d9849fbe9658052018-07-10Verified
Show 3 more filings ↓Show fewer ↑up to 1771d gap
- New Hampshire State AGbd_0f2d25b2273b13f32018-07-27 · +17dVerified by operator
- Massachusetts State AGbd_9f8a44684fb3d8bb2018-07-30 · +20dVerified by operator
- HHS OCR enforcementbd_43a0abb3eba49ad42023-05-16 · +1771dVerified by operator
Filing propagation · 8 filings · 5 states
View merged incident ↗Pattern: first filing Jul 10 (MA), last May 16 — a 1771-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.