HackingHealthcareProfessional ServicesHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)Downstream VictimsDelayed DiscoveryPHIPIIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHighResolved
Medusind, Inc.
bd_1c5c691e1494de49 · schema v1 · pii pii-v1
Full breach record for Medusind, Inc. →On December 29, 2023, Medusind, Inc., a revenue cycle management company serving health care organizations, discovered suspicious activity in its IT network. Investigation found evidence a cybercriminal may have obtained files containing patient personal information including health, insurance, payment, government ID, and other PII. Approximately 1,037 Maryland residents and 360,934 individuals nationwide were affected. Notification was sent in January 2025.
Maryland clock✗ MD AG >90d29 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,037 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376128.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 19, 2026
- Raw hash
- ba231cc04b5dc53b96fa8411357853054ccd1dc5788da163de16cf7f79dc2908
Reporting entity
- Name
- Medusind, Inc.norm: medusind
Victim entity
- Name
- Medusind, Inc.norm: medusind
- Industry
- Revenue cycle management / billing support for health care organizations
- Industry
- HealthcarellmProfessional Servicesllm
Incident
- Discovered
- Dec 29, 2023
- Materiality determined
- —
- Notification sent
- Jan 7, 2025
- Affected individuals
- 1,037
- Data types
- PHIPIIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1074 Data StagedT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General pursuant to Md. Code Ann., Com. Law § 14-3504Reported the incident to the FBI
Compliance
- Time to disclose
- 29 months(872 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.