TANDEM DIABETES CARE, INC.
ent_019e2069e549be77a21e99a09856368e
Disclosures
4
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
140,838
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TANDEM DIABETES CARE, INC.
- Normalized
- tandem diabetes care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JEPFOD0K4D3I05
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- CALIFORNIAHHS OCRas victim2020-03-17
Tandem Diabetes Care, Inc. reported to HHS on 2020-03-17 a Hacking/IT Incident affecting 140,781 individuals. Breached information located on Email. The cyber-attack involved electronic protected health information (ePHI) including names, dates of birth, addresses, Social Security numbers, diagnoses, medications, and treatment information. The entity provided substitute notice on its website and complimentary identity and credit monitoring services. The CE revised HIPAA security procedures and implemented additional technical safeguards.
- 🦫Oregon State AGas victim2020-03-17
Tandem Diabetes Care, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-03-17. The breach occurred during 1/17/2020 - 1/20/2020. The breach was discovered on 1/17/2020. 140,838 individuals were affected. Notice was sent on 3/17/2020.
- 🦬Montana State AGas victim2020-03-17
Tandem Diabetes Care, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2020-03-17. The breach occurred on 1/17/2020. 815 Montana residents were affected.
- 🐻California State AGas victim2020-03-17
Tandem Diabetes Care experienced a phishing incident where an unauthorized person gained access to employee email accounts between January 17 and January 20, 2020. The breach potentially exposed personal information including names, contact details, Social Security numbers, product usage data, and clinical diabetes therapy data. The company secured the accounts, engaged a cybersecurity firm, and offered one year of identity protection services to affected individuals.