DisclosureLens
AccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedPHIHealth (basic)PIILowResolved

ConvenientMD Urgent Care

bd_6f78089beac24f3b · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Jan 26, 2021

To disclose

Affected

130state residents only

Linked

2 filings

Confidence

66%
Full breach record for ConvenientMD Urgent Care3 incidents on file

ConvenientMD Urgent Care notified the NH Attorney General of a data security breach involving 130 New Hampshire residents. Between December 18 and 21, 2020, the company sent emails notifying individuals of available coronavirus test results. Due to a misconfiguration, all recipient email addresses were placed in the 'To' field rather than 'Bcc', exposing the email addresses of other recipients. This allowed recipients to see that others had been tested for coronavirus. No actual test results were included in the emails. ConvenientMD has corrected its email procedures.

Incident timeline

Dec 18, 2020

Begins

Jan 26, 2021

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGJan 22 · first
New Hampshire State AG+4d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.