DisclosureLens
AccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedPHIIdentity (basic)Health (basic)LowResolved

CardioFit Medical Group, Inc.

bd_d322ce828fe1498e · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 17, 2026

Filed

Apr 9, 2026

To disclose

7 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for CardioFit Medical Group, Inc.

CardioFit Medical Group, Inc. disclosed that between January 8 and February 5, 2026, protected health information was sent via unencrypted email. The incident was discovered on February 17, 2026. Affected data included names, demographic details, clinical information (diagnosis), and insurance information. No SSNs, bank accounts, or credit cards were involved. The organization strengthened email encryption procedures and provided staff training.

California clockDiscovered Feb 17, 2026Notified Apr 10, 202652d CA 30-day late7 weeks discovery → filing

Incident timeline

undetected · 40 days
discovery → filing · 7 weeks / 51 days

Jan 8, 2026

Begins

Feb 17, 2026

Discovered

Apr 9, 2026

Filed

vs. sector median

5 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRApr 9 · first
California State AGApr 9 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.