DisclosureLens
CALIFORNIAHackingHealthcareHealthcareStolen CredentialsPhishingCustomer Data InvolvedData ExfiltratedPHIHealth (basic)Identity (basic)Government IDHighResolved

INOGEN, INC.

bd_18bf03ad63467566 · schema v1 · pii pii-v1

Severity

High

Discovered

Apr 17, 2018

Filed

Apr 17, 2018

To disclose

Affected

29,528

Linked

7 filings

Confidence

67%
Full breach record for INOGEN, INC.

Inogen, Inc. reported to HHS on 2018-04-17 a Hacking/IT Incident affecting 29,528 individuals. Breached information located on Email. An unauthorized individual gained access to an employee email account and set up forwarding of messages from Jan 2, 2018 to Mar 14, 2018. Compromised PHI included names, addresses, DOBs, Medicare IDs, and medical equipment info. Inogen strengthened security controls including disabling email forwarding, password resets, and implementing dual-factor authentication.

HIPAA clockDiscovered Apr 17, 2018Notified Apr 17, 20180d HHS report on time
notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

undetected · 105 days
discovery → filing · ≤1 day / 0 days

Jan 2, 2018

Begins

Apr 17, 2018

Discovered

Apr 17, 2018

Filed

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 4d gap

Filing propagation · 7 filings · 6 states

View merged incident ↗
New Hampshire State AGApr 13 · first
Oregon State AGApr 13 · first
Montana State AGApr 13 · first
Massachusetts State AGApr 13 · first
California State AGApr 13 · first
Washington State AGApr 13 · first
HHS OCR+4d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.