MedEvolve
bd_a0496aa58a430ab5 · schema v1 · pii pii-v1
Full breach record for MedEvolve →MedEvolve, a healthcare billing services provider, notified New Hampshire regulators of a data breach affecting 84 state residents. On May 11, 2018, MedEvolve discovered an FTP file containing patient PII (names, SSNs, addresses) was inadvertently accessible online from March 29 to May 4, 2018, and subject to unauthorized access starting March 29. MedEvolve engaged forensic investigators, secured the portal, and provided 2 years of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 29, 2018
Begins
May 11, 2018
Discovered
Jul 10, 2018
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- California State AGbd_0bd4122eff0cddb42018-07-10Verified
- Massachusetts State AGbd_2cc6cf8c3756184a2018-07-10Verified
- HHS OCRbd_6ac38550f52fc8d32018-07-10Verified
- Montana State AGbd_a2d9849fbe9658052018-07-10Verified
Show 3 more filings ↓Show fewer ↑up to 1771d gap
- New Hampshire State AGbd_0f2d25b2273b13f32018-07-27 · +17dVerified by operator
- Massachusetts State AGbd_9f8a44684fb3d8bb2018-07-30 · +20dVerified by operator
- HHS OCR enforcementbd_43a0abb3eba49ad42023-05-16 · +1771dVerified by operator
Filing propagation · 8 filings · 5 states
View merged incident ↗Pattern: first filing Jul 10 (CA), last May 16 — a 1771-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.