ZOLL Medical
bd_15a1da436523208c · schema v1 · pii pii-v1
Full breach record for ZOLL Medical →ZOLL Medical Group experienced a cybersecurity incident on January 28, 2023, involving unauthorized access to its internal network. The incident potentially affected the protected health information and personal data of patients, employees, and their dependents, including names, addresses, Social Security numbers, and health/financial data. ZOLL notified law enforcement, engaged third-party forensic experts, and offered credit monitoring services. The investigation was ongoing as of the March 10, 2023 notification date, with specific affected counts reported for several states including Texas (105,306 patients) and Rhode Island (1,767 patients).
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0508d77c64b573f8Delaware State AGfiled 2023-03-10Candidate
- bd_142152a27cb186ddCalifornia State AGfiled 2023-03-10Verified
- bd_3dc114db9cf57c6fVermont State AGfiled 2023-03-10Verified
- bd_45b338a33a1fe783Washington State AGfiled 2023-03-10Verified
Show 3 more filings ↓Show fewer ↑up to 3d gap
- bd_bfd7269fa3840225Maine State AGfiled 2023-03-10Verified
- bd_e0ffd0dc853fa19dOregon State AGfiled 2023-03-10Verified
- bd_2bbe6c0aee4246d1New Hampshire State AGfiled 2023-03-13(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/03/Delaware-Notification-Letters.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2023
- Raw hash
- 757af0c2bf0641d83fc9cff6156141bd4c7f99ef11fce4a8a7b65abac6416d2c
Reporting entity
- Name
- ZOLL Medicalnorm: zoll medical
- Domain
- zoll.com
Victim entity
- Name
- ZOLL Medicalnorm: zoll medical
- Domain
- zoll.com
Incident
- Discovered
- Jan 28, 2023
- Materiality determined
- —
- Notification sent
- Mar 10, 2023
- Affected individuals
- 106,726
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal and state regulatory agencies as required by law
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.