DisclosureLens
CALIFORNIAHackingHealthcareHealthcareMisconfigurationCustomer Data InvolvedHealth (basic)Identity (basic)Medium

CardioFit Medical Group, Inc.

bd_d7c8cc88c2cb68aa · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 17, 2026

Filed

Apr 9, 2026

To disclose

Affected

7,243

Linked

2 filings

Confidence

79%
Full breach record for CardioFit Medical Group, Inc.

CardioFit Medical Group, Inc. (CA) reported to HHS OCR on 2026-04-09 an Unauthorized Access/Disclosure incident affecting 7,243 individuals. Breached information was located in Email. No business associate was identified as present. No further detail is available from the web description.

HIPAA clock HHS report on time
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 7 weeks / 51 days

Feb 17, 2026

Discovered

Apr 9, 2026

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
California State AGApr 9 · first
HHS OCRApr 9 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.