DisclosureLens
HackingHealthcareProfessional ServicesHealthcareCustomer Data InvolvedData ExfiltratedIdentity (basic)Government IDPHIHealth (basic)Financial accountCredentialsMediumContained

MedRevenu, LLC

bd_ee7c9906dc800598 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 12, 2024

Filed

Feb 3, 2026

To disclose

14 months

Affected

Not disclosed

Confidence

64%
Full breach record for MedRevenu, LLC3 incidents on file

MedRevenu, LLC, a healthcare billing services provider, notified the California Attorney General of a data security incident. The breach occurred on December 3, 2024, and was discovered on December 12, 2024, when a network disruption was detected. An investigation concluded in October 2025 that certain files containing personal information, including names, dates of birth, Social Security numbers, driver's license numbers, health insurance and medical information, and financial account numbers, may have been acquired without authorization. The company engaged cybersecurity experts, secured its network, and is offering 12 months of complimentary credit monitoring and fraud assistance to affected individuals.

California clockDiscovered Dec 12, 2024Notified Feb 3, 2026418d CA 60-day late14 months discovery → filing

Incident timeline

undetected · 9 days
discovery → filing · 14 months / 418 days

Dec 3, 2024

Begins

Dec 12, 2024

Discovered

Feb 3, 2026

Filed

vs. sector median

+47 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.