Insulet Corporation
ent_019e0d5821944dea3627ab65b0cac2f2
Disclosures
10
SEC 10-K Item 1C · HHS OCR · State AG · 5 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
9,050
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Insulet Corporation
- Normalized
- insulet— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300TZTYD2PYN92D43
- SEC EDGAR CIK
- 0001145197
- Domain
- insulet.com
Disclosure history (10)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-18
Insulet Corporation's 10-K Item 1C cybersecurity disclosure describes its risk-management program, governance, and incident-response framework. The company states it does not believe risks from cybersecurity threats, including any previous incidents, have materially affected its business, results of operations, or financial condition. No specific cybersecurity incident is disclosed in this filing.
- MASSACHUSETTSHHS OCRas victim2025-05-16
Insulet Corporation reported to HHS on 2025-05-16 a Unauthorized Access/Disclosure affecting 841 individuals. Breached information located on Network Server.
- 🐻California State AGas victim2023-01-10
Insulet Corporation disclosed a data privacy incident involving the exposure of limited protected health information (PHI) for Omnipod DASH customers. Due to a misconfiguration of web pages used for receipt verification of a Medical Device Correction letter, customer IP addresses, product usage status, and Personal Diabetes Manager usage were exposed to website performance and marketing partners via cookies and trackers. The incident occurred on December 1, 2022, and was discovered on December 6, 2022. Insulet disabled tracking codes and requested partner log deletion. No financial information, SSNs, emails, or passwords were exposed.
- 🦬Montana State AGas victim2023-01-09
Insulet Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2023-01-09. The breach occurred on 12/6/2022. 96 Montana residents were affected.
- 💎Delaware State AGas victim2023-01-05
Insulet Corporation disclosed a data privacy incident affecting Omnipod DASH customers. On or about December 1, 2022, the company sent MDC acknowledgment emails containing unique verification URLs. These URLs exposed customer IP addresses, Omnipod DASH usage, and Personal Diabetes Manager (PDM) usage to website performance and marketing partners via cookies and trackers. Insulet discovered the incident on December 6, 2022, and disabled the tracking codes that same day. No financial information, SSNs, emails, or passwords were exposed. The notice was sent to customers on January 5, 2023.
- 💎Delaware State AGas victim2022-12-21
Insulet Corporation disclosed a data privacy incident affecting Omnipod DASH customers. Between December 1 and December 6, 2022, web pages used for medical device correction (MDC) receipt verification exposed customer IP addresses, Omnipod DASH usage status, and Personal Diabetes Manager (PDM) usage to third-party marketing and performance partners via cookies. No financial data, SSNs, or passwords were exposed. Insulet disabled the tracking codes and requested partners delete logs.
- 🐻California State AGas victim2021-03-19
Insulet Corporation notified customers of a data security incident involving its vendor, Cornerstone On-Demand. An unauthorized third party gained access to Cornerstone's systems on January 13, 2021, potentially accessing and downloading customer names, email addresses, and training records. Insulet discovered the incident on January 19, 2021, when notified by the vendor. Cornerstone blocked access and implemented security measures. Insulet is transitioning to a new vendor and will require deletion of data.
- MASSACHUSETTSHHS OCRas victim2021-03-19
Insulet Corporation reported to HHS on 2021-03-19 a Hacking/IT Incident affecting 9050 individuals. Breached information located on Network Server. A business associate was the victim of a cyber-attack involving ePHI (names, addresses, treatment info). The BA retrained staff on recognizing fraudulent emails.
- 🦬Montana State AGas victim2021-03-18
Insulet Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-18. The breach occurred on 1/13/2021. 30 Montana residents were affected.
- FEDERALHHS OCRas victim2017-10-17
On August 18, 2017, Insulet Corporation reported a data breach involving its business associate, Brainshark Inc. A technical error led to the exposure of 3,732 customer email addresses to other customers. In response, the training module causing the error was deactivated, Brainshark disabled the site, and the incident was investigated. Insulet Corporation provided breach notifications to the Department of Health and Human Services (HHS) and the 1,469 affected individuals. As a corrective action, the company terminated its contract with Brainshark Inc.