Med-data incorporated
bd_d90333e30b1f3be6 · schema v1 · pii pii-v1
Full breach record for Med-data incorporated →Med-Data, Incorporated notified Montana residents of a data security incident involving PHI. A former employee saved files containing patient data to personal folders on a public-facing website between Dec 2018 and Sep 2019. The files were discovered on Dec 10, 2020, and removed on Dec 17, 2020. Med-Data engaged cybersecurity specialists, implemented new security controls (SOC, MDR, blocked file sharing), and offered credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 1, 2018
Begins
Dec 10, 2020
Discovered
Mar 31, 2021
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Hawaii State AGbd_073059a1d70c76a32021-03-31Candidate
- Indiana State AGbd_92cf2578eac8ebec2021-03-31Verified
- HHS OCRbd_14e81bc1118830f02021-04-01 · +1dVerified
- New Hampshire State AGbd_01572e11b991a8d22021-04-08 · +8dVerified
Show 4 more filings ↓Show fewer ↑up to 107d gap
- Massachusetts State AGbd_9d43a830832396952021-04-26 · +26dVerified
- California State AGbd_d2fbe94657d113f02021-04-26 · +26dVerified
- Oregon State AGbd_28ea87358d1eeb422021-05-05 · +35dVerified
- Maine State AGbd_52a39a7ea123b7a32021-07-16 · +107dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Mar 31 (HI), last Jul 16 (ME) — a 107-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.