medQ, Inc.
bd_5a44626b9e34f658 · schema v1 · pii pii-v1
Full breach record for medQ, Inc. →2 incidents on filemedQ, Inc. experienced a ransomware incident where files were encrypted and exfiltrated from its software platform hosted by a third-party data center between December 20-26, 2023. The breach affected individuals' PHI, including names, SSNs, driver's license numbers, diagnoses, and treatment information. medQ disconnected the network, engaged forensic investigators, and is offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 20, 2023
Begins
Dec 26, 2023
Discovered
Feb 23, 2024
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- HHS OCRbd_47b1f8800add20a62024-02-23Verified
- Massachusetts State AGbd_bb9314f65e0432352024-02-23Verified
- Indiana State AGbd_bdb2089ed777401b2024-02-23Verified
- Maine State AGbd_dcfa5a8e797d467d2024-02-23Candidate
Show 3 more filings ↓Show fewer ↑up to 96d gap
- Montana State AGbd_e84e7d460997ea882024-02-23Verified
- New Hampshire State AGbd_c4a29c2a879476bb2024-03-13 · +19dVerified
- California State AGbd_7756d64c62956c672024-05-29 · +96dVerified
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Feb 23 (TX), last May 29 (CA) — a 96-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.