MisusePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENTMediumContained
United States Medical Supply, LLC.
bd_6eac3fe32c901ea4 · schema v1 · pii pii-v1
Full breach record for United States Medical Supply, LLC. →United States Medical Supply notified Vermont AG of a security incident where an unauthorized individual, facilitated by an employee, accessed customer data including names, DOBs, addresses, health diagnoses, and patient IDs. The employee was terminated. US MED is updating policies and offering 24 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ffd43de97bfefcf8Indiana State AGfiled 2024-01-12Verified
- bd_06d242f75967dabaMontana State AGfiled 2024-01-24(12d gap)Verified
- bd_d0fcf7a397b6a25fNew Hampshire State AGfiled 2024-01-24(12d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-12-united-states-medical-supply-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2024
- Raw hash
- 00177aed6f8f266d9d2595b75d8d8c1684dd4e54a76dd40e12ca7b731ea1617b
Reporting entity
- Name
- United States Medical Supply, LLC.norm: united states medical supply
- Domain
- drivemedical.com
Victim entity
- Name
- United States Medical Supply, LLC.norm: united states medical supply
- Domain
- drivemedical.com
Incident
- Discovered
- Nov 13, 2023
- Materiality determined
- —
- Notification sent
- Jan 12, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.