CardioFit Medical Group, Inc.
bd_d322ce828fe1498e · schema v1 · pii pii-v1
Full breach record for CardioFit Medical Group, Inc. →CardioFit Medical Group, Inc. disclosed that between January 8 and February 5, 2026, protected health information was sent via unencrypted email. The incident was discovered on February 17, 2026. Affected data included names, demographic details, clinical information (diagnosis), and insurance information. No SSNs, bank accounts, or credit cards were involved. The organization strengthened email encryption procedures and provided staff training.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 8, 2026
Begins
Feb 17, 2026
Discovered
Apr 9, 2026
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_d7c8cc88c2cb68aa2026-04-09Candidate
Filing propagation · 2 filings
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.