DisclosureLens
AccidentalTechnologyHealthcareInformationMisdeliveryData ExfiltratedIdentity (basic)Government IDPIIMediumActive

MedEvolve

bd_a2d9849fbe965805 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 11, 2018

Filed

Jul 10, 2018

To disclose

9 weeks

Affected · nationwide

1513 in this filing

Linked

8 filings

Confidence

65%
Full breach record for MedEvolve

MedEvolve notified Montana residents of a data breach where an FTP file containing patient PII (names, SSNs, addresses) was inadvertently accessible online from March 29 to May 4, 2018. Unauthorized access occurred on March 29, 2018. 15 individuals were affected. MedEvolve engaged forensic investigators and offered 2 years of credit monitoring.

Incident timeline

undetected · 43 days
discovery → filing · 9 weeks / 60 days

Mar 29, 2018

Begins

May 11, 2018

Discovered

Jul 10, 2018

Filed

vs. sector median

10 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 1771d gap

Filing propagation · 8 filings · 5 states

View merged incident ↗
California State AGJul 10 · first
Massachusetts State AGJul 10 · first
HHS OCRJul 10 · first
New Hampshire State AGJul 10 · first
Montana State AGJul 10 · first · this page

Pattern: first filing Jul 10 (CA), last May 16 — a 1771-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.