MedEvolve
bd_0bd4122eff0cddb4 · schema v1 · pii pii-v1
Full breach record for MedEvolve →MedEvolve, a healthcare billing services provider, disclosed a data breach affecting 15 patients. On March 29, 2018, an FTP server containing patient data was inadvertently made accessible to the internet. The breach exposed names, billing addresses, phone numbers, health insurer details, account numbers, and Social Security numbers. The exposure lasted until May 4, 2018, when unauthorized access occurred. A screenshot of the data was posted online. MedEvolve engaged forensic investigators, secured the portal, and notified HHS, media, and state regulators. Affected individuals received two years of complimentary credit monitoring.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a2d9849fbe965805Montana State AGfiled 2018-07-10Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-137784
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2018
- Raw hash
- e7b6de3316cbaa3e249629e189c272e5923101e73d78f1f1c8b77623f70376ac
Reporting entity
- Name
- MedEvolvenorm: medevolve
Victim entity
- Name
- MedEvolvenorm: medevolve
Incident
- Discovered
- May 11, 2018
- Materiality determined
- Mar 29, 2018
- Notification sent
- —
- Affected individuals
- 15
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.