Insulet Corporation
bd_4b77c0e779b47ea3 · schema v1 · pii pii-v1
Full breach record for Insulet Corporation →Insulet Corporation disclosed a data privacy incident affecting Omnipod DASH customers. On or about December 1, 2022, the company sent MDC acknowledgment emails containing unique verification URLs. These URLs exposed customer IP addresses, Omnipod DASH usage, and Personal Diabetes Manager (PDM) usage to website performance and marketing partners via cookies and trackers. Insulet discovered the incident on December 6, 2022, and disabled the tracking codes that same day. No financial information, SSNs, emails, or passwords were exposed. The notice was sent to customers on January 5, 2023.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_b72b9465f971309eMontana State AGfiled 2023-01-09(4d gap)Verified
- bd_09375a81f3d038e8California State AGfiled 2023-01-10(5d gap)Verified
- bd_c92cd96665cb3150Delaware State AGfiled 2022-12-21(15d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/01/Notice-to-Customers.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2023
- Raw hash
- 5a2b66bf4f2e57103cf485352a0200ee4d3d2e846f69d4545c4b698a2aaf16a2
Reporting entity
- Name
- Insulet Corporationnorm: insulet
- Domain
- insulet.com
Victim entity
- Name
- Insulet Corporationnorm: insulet
- Domain
- insulet.com
Incident
- Discovered
- Dec 6, 2022
- Materiality determined
- —
- Notification sent
- Jan 5, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIPHILOCATION
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1071 Application Layer Protocol
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.