Insulet Corporation
ent_019e0d5821944dea3627ab65b0cac2f2
Disclosures
17
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
29,000
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Insulet Corporation
- Normalized
- insulet— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300TZTYD2PYN92D43
- SEC EDGAR CIK
- 0001145197
- Domain
- insulet.com
Disclosure history (17)newest first
- MASSACHUSETTSHHS OCRas victim2025-05-16
Insulet Corporation reported to HHS on 2025-05-16 a Unauthorized Access/Disclosure affecting 841 individuals. Breached information located on Network Server.
- Illinois State AGas victim2025-05-01
INSULET CORPORATION filed a data-breach notice with the Illinois Attorney General in May 2025 (case 25-05-197). The register records the breach as discovered on March 19, 2025. Personal information types reported: drivers license. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2025-02-01
INSULET CORPORATION filed a data-breach notice with the Illinois Attorney General in February 2025 (case 25-02-139). The register records the breach as discovered on February 7, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2023-01-10
Insulet Corporation disclosed a data privacy incident involving the exposure of limited protected health information (PHI) for Omnipod DASH customers. Due to a misconfiguration of web pages used for receipt verification of a Medical Device Correction letter, customer IP addresses, product usage status, and Personal Diabetes Manager usage were exposed to website performance and marketing partners via cookies and trackers. The incident occurred on December 1, 2022, and was discovered on December 6, 2022. Insulet disabled tracking codes and requested partner log deletion. No financial information, SSNs, emails, or passwords were exposed.
- Montana State AGas victim2023-01-09
Insulet Corporation disclosed a data privacy incident where web page configuration exposed customer IP addresses, Omnipod DASH usage, and Personal Diabetes Manager usage to marketing partners via cookies. Discovered Dec 6, 2022. No financial or SSN data exposed.
- MASSACHUSETTSHHS OCRas victim2023-01-05
Insulet Corporation reported to HHS on 2023-01-05 a Unauthorized Access/Disclosure affecting 29,000 individuals. Breached information located on Network Server. The entity inadvertently used tracking devices on its computer systems that captured the protected health information (PHI) of 29,000 individuals. The PHI involved included names and IP addresses. The CE notified HHS, affected individuals and the media of the breach. In its mitigation efforts, the CE implemented additional technical safeguards to better protect PHI.
- Delaware State AGas victim2023-01-05
Insulet Corporation disclosed a data privacy incident affecting Omnipod DASH customers. On or about December 1, 2022, the company sent MDC acknowledgment emails containing unique verification URLs. These URLs exposed customer IP addresses, Omnipod DASH usage, and Personal Diabetes Manager (PDM) usage to website performance and marketing partners via cookies and trackers. Insulet discovered the incident on December 6, 2022, and disabled the tracking codes that same day. No financial information, SSNs, emails, or passwords were exposed. The notice was sent to customers on January 5, 2023.
- Washington State AGas victim2023-01-05
Insulet Corporation disclosed a privacy incident where configuration of web pages for receipt verification exposed customer IP addresses, Omnipod DASH usage, and Personal Diabetes Manager usage to marketing partners. Discovered Dec 6, 2022. Tracking codes disabled immediately. No financial info or SSNs exposed.
- Illinois State AGas victim2023-01-01
INSULET CORPORATION filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-196). The register records the breach as discovered on December 6, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Delaware State AGas victim2022-12-21
Insulet Corporation disclosed a data privacy incident affecting Omnipod DASH customers. Between December 1 and December 6, 2022, web pages used for medical device correction (MDC) receipt verification exposed customer IP addresses, Omnipod DASH usage status, and Personal Diabetes Manager (PDM) usage to third-party marketing and performance partners via cookies. No financial data, SSNs, or passwords were exposed. Insulet disabled the tracking codes and requested partners delete logs.
- California State AGas victim2021-03-19
Insulet Corporation notified customers of a data security incident involving its vendor, Cornerstone On-Demand. An unauthorized third party gained access to Cornerstone's systems on January 13, 2021, potentially accessing and downloading customer names, email addresses, and training records. Insulet discovered the incident on January 19, 2021, when notified by the vendor. Cornerstone blocked access and implemented security measures. Insulet is transitioning to a new vendor and will require deletion of data.
- MASSACHUSETTSHHS OCRas victim2021-03-19
Insulet Corporation reported to HHS on 2021-03-19 a Hacking/IT Incident affecting 9050 individuals. Breached information located on Network Server. A business associate was the victim of a cyber-attack involving ePHI (names, addresses, treatment info). The BA retrained staff on recognizing fraudulent emails.
- Montana State AGas victim2021-03-18
Insulet Corporation notified Montana DOJ that its vendor, Cornerstone On-Demand, experienced unauthorized access on Jan 13, 2021. Insulet learned of the incident on Jan 19, 2021. Access involved names, emails, and training records. Insulet is transitioning platforms and requiring data deletion.
- Illinois State AGas victim2021-01-01
INSULET CORPORATION filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-138). The register records the breach as discovered on January 19, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
INSULET COPORATION filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-091). The register records the breach as discovered on April 25, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2019-01-01
INSULET CORP. filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-144). The register records the breach as discovered on December 18, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- MASSACHUSETTSHHS OCRas victim2017-10-17
On August 18, 2017, Insulet Corporation reported a data breach involving its business associate, Brainshark Inc. A technical error led to the exposure of 3,732 customer email addresses to other customers. In response, the training module causing the error was deactivated, Brainshark disabled the site, and the incident was investigated. Insulet Corporation provided breach notifications to the Department of Health and Human Services (HHS) and the 1,469 affected individuals. As a corrective action, the company terminated its contract with Brainshark Inc.