MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedDownstream VictimsBusiness Associate (HIPAA)PHIIDENTITY_BASICLowContained
MedInform, Inc.
bd_64afa89f350e71b1 · schema v1 · pii pii-v1
Full breach record for MedInform, Inc. →MedInform, Inc. notified the NH AG of a security event affecting 1 NH resident. Suspicious activity identified Dec 21, 2022 involving malicious encryption. Unauthorized access occurred Dec 5-21, 2022. Unencrypted PHI of Cleveland Clinic patients was exfiltrated. MedInform engaged third-party specialists, notified law enforcement and HHS, and offered 24 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d7ba3bdbe803744aMontana State AGfiled 2023-05-24(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/medinform-20230531.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2023
- Raw hash
- 9daaf59c914ed5243a125fd3656a7daef27968c8943efcb932363572aca8e05d
Reporting entity
- Name
- MedInform, Inc.norm: medinform
Victim entity
- Name
- MedInform, Inc.norm: medinform
Incident
- Discovered
- Dec 21, 2022
- Materiality determined
- —
- Notification sent
- May 24, 2023
- Affected individuals
- 1
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the event to federal law enforcementProvided written notice to the U.S. Department of Health and Human ServicesProvided written notice to appropriate state privacy regulatorsProvided written notice to the three major consumer reporting agencies
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.