MalwareRansomwareData EncryptedTargetedIDENTITY_BASICHEALTH_BASICPIILowContained
MedPeds Associates of Sarasota
bd_f5fef79475594d25 · schema v1 · pii pii-v1
Full breach record for MedPeds Associates of Sarasota →MedPeds Associates of Sarasota notified Vermont AG on 2026-03-16 of a September 2, 2025 incident where an intruder encrypted patient data. Affected data included names, DOBs, addresses, phone numbers, and medical records. The company engaged forensic investigators, contacted the FBI, and implemented additional web server safeguards. No evidence of data misuse was found at the time of notice.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4e606e92c99d6162Maine State AGfiled 2026-03-16Verified
- bd_bf13059c2b0bb4a6Indiana State AGfiled 2026-03-16Verified
- bd_693ed259aa941ef6HHS OCRfiled 2026-03-13(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-16-medpeds-associates-sarasota-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 16, 2026
- Raw hash
- 5694d0fa2fb60f86c2ac5bbfb46c68219b244a6174e1ee9b007fdd0efb28c818
Reporting entity
- Name
- MedPeds Associates of Sarasotanorm: medpeds associates of sarasota
Victim entity
- Name
- MedPeds Associates of Sarasotanorm: medpeds associates of sarasota
Incident
- Discovered
- Sep 2, 2025
- Materiality determined
- Mar 16, 2026
- Notification sent
- Mar 16, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the FBI and worked with their cyber security department
Compliance
- Time to disclose
- 28 weeks(195 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.