DisclosureLens
HackingHealthcareRetail & ConsumerHealthcareData ExfiltratedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountHealth (basic)EmploymentMediumActive

Medical Depot, Inc.

bd_c5ab5e466b2c428d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 4, 2020

Filed

Sep 14, 2020

To disclose

15 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Medical Depot, Inc.3 incidents on file

Medical Depot, Inc. (d/b/a Drive DeVilbiss Healthcare) disclosed that an unauthorized third party gained remote access to its network on or about June 4, 2020. The actor acquired and briefly possessed an electronic file system containing internal company information, including employee and beneficiary data such as names, SSNs, bank account numbers, tax IDs, and health condition information. The company engaged cybersecurity experts, contacted law enforcement, and offered credit monitoring. The investigation was ongoing at the time of notification.

California clockDiscovered Jun 4, 2020Notified Jul 3, 202029d CA 60-day OK15 weeks discovery → filing

Incident timeline

undetected · 10 days
discovery → filing · 15 weeks / 102 days

May 25, 2020

Begins

Jun 4, 2020

Discovered

Sep 14, 2020

Filed

vs. sector median

+2 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Maine State AGSep 14 · first
California State AGSep 14 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.