DisclosureLens
AccidentalHealthcareTechnologyHealthcareMisconfigurationCustomer Data InvolvedData ExfiltratedPIIIdentity (basic)AuthenticationCredentialsLocationBehaviorMinorHighContained

MEDTRONIC MINIMED, INC.

bd_4e71eefd8325beec · schema v1 · pii pii-v1

Severity

High

Discovered

Feb 13, 2023

Filed

Apr 14, 2023

To disclose

9 weeks

Affected

58,374state residents only

Confidence

66%
Full breach record for MEDTRONIC MINIMED, INC.2 incidents on file

Medtronic MiniMed disclosed that tracking technologies (Google Analytics, Crashlytics, Firebase Auth) in its InPen App inadvertently transmitted user data to Google starting Sept 2020. Discovered Feb 13, 2023. Data included emails, IPs, passwords, and device IDs. No SSN or financial data. Notifications sent April 14, 2023. Google Analytics removed; migration to new platforms underway.

Incident timeline

discovery → filing · 9 weeks / 60 days

Feb 13, 2023

Discovered

Apr 14, 2023

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed58,374 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.