HackingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Medusind, Inc.
bd_44842e5c901da36a · schema v1 · pii pii-v1
Full breach record for Medusind, Inc. →Medusind, Inc., a revenue cycle management company, experienced a cyber incident on December 29, 2023, which was discovered the same day. A cybercriminal may have obtained copies of files containing personal information, including health insurance/billing data, payment information, health information, government IDs (SSN, driver's license), and other PII. Medusind took systems offline, engaged forensic investigators, and is offering two years of identity monitoring via Kroll.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_166adc1614e76acdDelaware State AGfiled 2025-01-07Verified
- bd_4c0617bdd3903364Indiana State AGfiled 2025-01-07Verified
- bd_853cd6d42e42a889Oregon State AGfiled 2025-01-07Candidate
- bd_c91dd71a3986d50cHHS OCRfiled 2025-01-07Verified
Show 4 more filings ↓Show fewer ↑up to 35d gap
- bd_e7e2fd3d471ae780Maine State AGfiled 2025-01-07Verified
- bd_bef150eaeee5f6b3Oregon State AGfiled 2025-02-11(35d gap)Verified
- bd_e16e595df9c8d7edCalifornia State AGfiled 2025-02-11(35d gap)Verified
- bd_e8a96821895972c9Washington State AGfiled 2025-02-11(35d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-597072
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 7, 2025
- Raw hash
- 03525ca5e069cb715f07f1c71ae1d1db7bcaf4530c087296d5322b960aab7917
Reporting entity
- Name
- Medusind, Inc.norm: medusind
Victim entity
- Name
- Medusind, Inc.norm: medusind
Incident
- Discovered
- Dec 29, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 13 months(375 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.