DJO, LLC
ent_019ebb2e9f32b6d9c209905ca554e41e
Disclosures
8
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
68,857
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DJO, LLC
- Normalized
- djo— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300OOBIBAJ6SRKG68
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- djoglobal.com
Disclosure history (8)newest first
- Massachusetts State AGas victim2021-01-21
DJO Global, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-21. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-12-23
DJO Global, Inc. disclosed a cyberattack where attackers staged and likely exfiltrated data between Nov 8-9, 2020. DJO learned of the incident on Nov 16, 2020. Affected data included SSNs, driver's licenses, medical/health insurance info, financial account info, and employment records. The company engaged a cybersecurity firm, strengthened security measures, and offered 24 months of credit monitoring.
- Montana State AGas victim2020-12-23
DJO Global, Inc. notified Montana residents of a cyberattack occurring Nov 8-9, 2020. Attackers exfiltrated PII including SSNs, driver's licenses, PHI, and financial data. DJO discovered the incident on Nov 16, 2020, and engaged a cybersecurity firm. Affected individuals received 24 months of credit monitoring.
- Indiana State AGas victim2020-12-23
DJO Global, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-11-08 and was reported on 2020-12-23. 16 Indiana residents were affected. 2,033 individuals affected in total.
- CALIFORNIAHHS OCRas victim2020-10-16
DJO, LLC (CA) reported to HHS on 2020-10-16 that an employee of its former business associate was the victim of an email phishing attack affecting the ePHI of 3,429 individuals. Breached information was located in Email. Exposed data included names, Social Security numbers, dates of birth, addresses, health insurance information, and medical diagnoses and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. OCR obtained assurances that corrective actions were implemented.
- CALIFORNIAHHS OCRas victim2018-01-06
DJO, LLC, a supplier of durable medical equipment, reported to HHS on January 6, 2018, a breach affecting 1,203 individuals. The incident involved the loss of paper forms by its business associate, Total Orthopedics. The breached protected health information included demographic and clinical information, product order dates, health insurer details, and health insurance indemnification numbers, which could potentially match social security numbers.
- Massachusetts State AGas victim2008-12-17
DJO, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-12-17. 14 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2008-12-12
DJO, LLC notified the NH AG of a laptop theft from third-party billing vendor Creditek LLC on Nov 14, 2008. The stolen device contained PHI and PII (SSN, DOB, names, addresses) for ~68,857 individuals nationwide, including 2 in NH. DJO and Creditek planned to notify affected individuals by Dec 10, 2008.