IMX Medical Management Services
bd_b8ed4b75ca4558a8 · schema v1 · pii pii-v1
Full breach record for IMX Medical Management Services →IMX Medical Management Services, Inc. disclosed a security incident discovered on September 1, 2022, involving malware on a laptop as early as June 2022. The threat actor accessed certain IMX systems and devices through October 2022, gaining access to email bodies and server folders containing personal and protected health information of claimants. IMX took systems offline, engaged in forensic investigation, and notified law enforcement. The company established a new network via parent company QTC Management, Inc., and offered two years of credit monitoring to affected individuals.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2e2054c4e4e8be0aCalifornia State AGfiled 2023-07-27Verified
- bd_63cfb5515213776eMontana State AGfiled 2023-07-27Verified
- bd_6f2f10518da13a8eDelaware State AGfiled 2023-07-27Verified
- bd_127ca3a499b242cdMaine State AGfiled 2023-07-12(15d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-27-imx-medical-management-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- 9671fd7476ccde7bbb21cd3402cafd72f8fded960b26f50c16caedd8f381f631
Reporting entity
- Name
- IMX Medical Management Servicesnorm: imx medical management
Victim entity
- Name
- IMX Medical Management Servicesnorm: imx medical management
Incident
- Discovered
- Sep 1, 2022
- Materiality determined
- —
- Notification sent
- Jul 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 47 weeks(329 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.