HackingData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTAUTHENTICATIONMediumResolved
Innovex International, Inc.
bd_37eace11cc2b7b76 · schema v1 · pii pii-v1
Full breach record for Innovex International, Inc. →Innovations Group, Inc. (IGI), a subsidiary of UpHealth, Inc., disclosed a data breach affecting its subsidiaries (MedQuest, Medical Horizons, Worldlink Medical, Pinnacle Labs). The breach, occurring Oct 27-30, 2021, exposed PHI and PII including SSNs, driver's licenses, medical records, and payment card data. IGI engaged forensic experts, secured systems, notified law enforcement, and offered one year of Equifax credit monitoring.
California clockDiscovered Nov 18, 2021 → Notified Dec 23, 202135d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8f0a2d6b8f892b6bMontana State AGfiled 2021-12-23Verified
- bd_70014d542fc8b53eWashington State AGfiled 2021-12-29(6d gap)Candidate
- bd_24e86d9369b8465aOregon State AGfiled 2022-01-03(11d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548872
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2021
- Raw hash
- 5ddc721479717d297885e342a0bc5174b9b5f2ac65e4db91ff6d91918fe5ec51
Reporting entity
- Name
- Innovations Group, Inc., a subsidiary of UpHealth, Inc.norm: innovations group inc a subsidiary of uphealth
Victim entity
- Name
- Innovex International, Inc.norm: innovex international
Incident
- Discovered
- Nov 18, 2021
- Materiality determined
- —
- Notification sent
- Dec 23, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 35d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 18, 2021→ Notified: Dec 23, 202135d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.