MedEvolve
bd_6ac38550f52fc8d3 · schema v1 · pii pii-v1
Full breach record for MedEvolve →MedEvolve, Inc. reported to HHS on 2018-07-10 a Unauthorized Access/Disclosure affecting 230,572 individuals. Breached information located on Network Server. The breach resulted from the misconfiguration of an FTP server, exposing PHI including names, SSNs, and account numbers. MedEvolve paid a $350,000 settlement and agreed to a corrective action plan including risk analysis, policy updates, and enhanced training.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 1, 2018
Discovered
Jul 10, 2018
Filed
vs. sector median
11 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- California State AGbd_0bd4122eff0cddb42018-07-10Verified
- Massachusetts State AGbd_2cc6cf8c3756184a2018-07-10Verified
- New Hampshire State AGbd_a0496aa58a430ab52018-07-10Verified
- Montana State AGbd_a2d9849fbe9658052018-07-10Verified
Show 3 more filings ↓Show fewer ↑up to 1771d gap
- New Hampshire State AGbd_0f2d25b2273b13f32018-07-27 · +17dVerified by operator
- Massachusetts State AGbd_9f8a44684fb3d8bb2018-07-30 · +20dVerified by operator
- HHS OCR enforcementbd_43a0abb3eba49ad42023-05-16 · +1771dVerified by operator
Filing propagation · 8 filings · 5 states
View merged incident ↗Pattern: first filing Jul 10 (CA), last May 16 — a 1771-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.