Medtronic, Inc.
ent_019ebb28a799891b9e609a795f4bdf09
Disclosures
12
State AG · SEC 10-K Item 1C · HHS OCR · 12 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
3,834,294
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Medtronic, Inc.
- Normalized
- medtronic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- D56MRZY2INAN94ZONZ37
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- ⭐Texas State AGas victim2026-06-30
Medtronic Inc. based in Minneapolis, Minnesota, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-15 and reported on 2026-06-30. 297,307 Texas residents were affected. 3,834,294 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Date of Birth. Consumers were notified via U.S. Mail.
- 🐻California State AGas victim2026-06-29
Medtronic Inc. reported a cybersecurity incident where an unauthorized actor accessed corporate IT systems from April 13-19, 2026. Medtronic became aware of unusual activity on April 15, 2026. Affected data includes names, contact info, dates of birth, Social Security numbers, and health-related information for patients with Medtronic devices. The company engaged third-party cybersecurity experts, notified law enforcement and regulators, and is offering 24 months of credit and identity monitoring services. No evidence suggests data was publicly posted.
- ⛰️New Hampshire State AGas victim2026-06-29
Medtronic Inc. notified the New Hampshire Attorney General on June 29, 2026, of a cybersecurity incident occurring between April 13 and 19, 2026. An unauthorized actor accessed corporate IT systems, potentially exposing personal information of 12,215 New Hampshire residents, including names, contact info, DOB, SSN, and health-related data. Medtronic engaged third-party cybersecurity experts, notified law enforcement and consumer reporting agencies, and offered 24 months of credit monitoring and identity theft restoration services. Device safety was not impacted.
- 🌲Washington State AGas victim2026-06-29
Medtronic Inc., a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2026-04-15 and filed notice on 2026-06-29. 64,035 Washington residents were affected. 75 days elapsed between awareness and notification. 2 days to identify the breach. 4 days to contain the breach.
- 🏎️Indiana State AGas victim2026-06-29
Medtronic Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2026-04-13 and was reported on 2026-06-29. 90,889 Indiana residents were affected. 3,834,294 individuals affected in total.
- 🦫Oregon State AGas victim2026-06-29
Medtronic Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-06-29. The breach occurred during 4/13/2026 - 4/19/2026. The breach was discovered on 4/15/2026. 3,834,294 individuals were affected. Notice was sent on 6/29/2026.
- 💎Delaware State AGas victim2026-06-29
Medtronic Inc. disclosed a cybersecurity incident affecting Rhode Island residents. Unauthorized actors accessed corporate IT systems between April 13 and 19, 2026. Impacted data included names, contact info, DOB, SSN, and health-related information. Medtronic engaged third-party cybersecurity experts, worked with law enforcement, and offered 24 months of credit monitoring and identity theft restoration via Epiq. The incident did not affect device safety.
- 🍁Vermont State AGas victim2026-06-28
Medtronic Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-06-28. The reporting organization type is Health Care. 8,668 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- 🏛️Massachusetts State AGas victim2026-06-01
Medtronic Inc. filed a breach notification with the Massachusetts Attorney General regarding a cybersecurity incident involving personal information. The company is offering 24 months of complimentary credit monitoring, dark web monitoring, and identity theft restoration services through Epiq to affected individuals. The notice provides guidance on placing security freezes and fraud alerts with credit bureaus.
- FEDERALSEC 10-K Item 1Cas victim2024-06-20
Medtronic's 10-K Item 1C cybersecurity disclosure describes its NIST CSF 2.0-based cybersecurity risk management program, incident response planning, third-party risk assessments, employee training, and governance structure (CISO reporting to CIO; Board Quality and Audit Committees oversight). The Company states it is not aware of any cybersecurity incident that has had, or is reasonably likely to have, a material impact on its business or operations. No specific incident is disclosed.
- 🦬Montana State AGas victim2016-07-08
Medtronic reported a data breach to the Montana Attorney General. The breach was reported on 2016-07-08. The breach occurred on 5/11/2016. 1 Montana residents were affected.
- MNHHS OCRas victim2013-07-10
Medtronic, Inc. reported to HHS on 2013-07-10 a Theft affecting 2764 individuals. Breached information located on Paper/Films. The covered entity misplaced a box of paper records containing patient pump training records, patient names, device serial numbers, phone numbers, email addresses, and potentially social security numbers and medical records.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of Medtronic, Inc. — not by Medtronic, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.