HackingData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTMediumActive
Medical Depot, Inc.
bd_c5ab5e466b2c428d · schema v1 · pii pii-v1
Full breach record for Medical Depot, Inc. →Medical Depot, Inc. (d/b/a Drive DeVilbiss Healthcare) disclosed that an unauthorized third party gained remote access to its network on or about June 4, 2020. The actor acquired and briefly possessed an electronic file system containing internal company information, including employee and beneficiary data such as names, SSNs, bank account numbers, tax IDs, and health condition information. The company engaged cybersecurity experts, contacted law enforcement, and offered credit monitoring. The investigation was ongoing at the time of notification.
California clockDiscovered Jun 4, 2020 → Notified Jul 3, 202029d ✓ CA 60-day OK15 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8485fc230aeb8256Maine State AGfiled 2020-09-14Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194044
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 14, 2020
- Raw hash
- 132163293755310ed0d94cdbce90d736eb48b3394ca97bf0b0fcecf6bea5b189
Reporting entity
- Name
- Medical Depot, Inc.norm: medical depot
- Domain
- drivemedical.com
Victim entity
- Name
- Medical Depot, Inc.norm: medical depot
- Domain
- drivemedical.com
Incident
- Discovered
- Jun 4, 2020
- Materiality determined
- —
- Notification sent
- Jul 3, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 4, 2020→ Notified: Jul 3, 202029d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.