AccidentalData MishandlingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
BioTel Heart (a trade name under which both CardioNet, LLC and LifeWatch, Inc. operate)
bd_80973f0a43e0f28c · schema v1 · pii pii-v1
Full breach record for BioTel Heart (a trade name under which both CardioNet, LLC and LifeWatch, Inc. operate) →BioTel Heart (CardioNet, LLC / LifeWatch, Inc.) disclosed a breach involving a vendor's failure to secure patient data stored online. The incident occurred between October 17, 2019, and August 9, 2020. Affected data included names, contact info, DOB, SSN, and medical records for remote cardiac monitoring patients. The vendor secured the data on August 9, 2020, and the business relationship was terminated. No evidence of misuse was found. Affected individuals were offered two years of Equifax credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539524
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2021
- Raw hash
- 979576cf771b3ca3e54f03fa0481447cc8880b506cb05788fdb4900ed408f644
Reporting entity
- Name
- BioTel Heart (a trade name under which both CardioNet, LLC and LifeWatch, Inc. operate)norm: biotel heart a trade name under which both cardionet llc and lifewatch inc operate
Victim entity
- Name
- BioTel Heart (a trade name under which both CardioNet, LLC and LifeWatch, Inc. operate)norm: biotel heart a trade name under which both cardionet llc and lifewatch inc operate
Incident
- Discovered
- Jan 28, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.