MalwareCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICPIILowContained
IMX Medical Management Services
bd_2e2054c4e4e8be0a · schema v1 · pii pii-v1
Full breach record for IMX Medical Management Services →IMX Medical Management Services, Inc. discovered malware on a laptop in September 2022, with indicators possibly dating to June 2022. A threat actor accessed email bodies and server folders containing PHI and PII for claimants, employees, and providers through October 2022. IMX took systems offline, engaged forensics, notified law enforcement, and migrated to a new network operated by parent company QTC. No evidence of exfiltration was confirmed, but access to email bodies occurred.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_63cfb5515213776eMontana State AGfiled 2023-07-27Verified
- bd_6f2f10518da13a8eDelaware State AGfiled 2023-07-27Verified
- bd_b8ed4b75ca4558a8Vermont State AGfiled 2023-07-27Verified
- bd_127ca3a499b242cdMaine State AGfiled 2023-07-12(15d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570964
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- 952422c2304035ac853b6d84f27da9513d0f48f464a39191c1a26bc8e7f122f1
Reporting entity
- Name
- IMX Medical Management Servicesnorm: imx medical management
Victim entity
- Name
- IMX Medical Management Servicesnorm: imx medical management
Incident
- Discovered
- Sep 1, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICPII
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement about the incident
Compliance
- Time to disclose
- 47 weeks(329 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.