CPAP Medical Supplies and Services Inc.
ent_4a8f9a94be3529499d7dee60
Disclosures
9
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
90,133
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CPAP Medical Supplies and Services Inc.
- Normalized
- cpap medical supplies and— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cpapmedical.com
Disclosure history (9)newest first
- New Hampshire State AGas victim2025-08-22
CPAP Medical Supplies and Services Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 154 NH residents. Unauthorized access occurred between Dec 13-21, 2024; discovered June 27, 2025. Compromised data included names, SSNs, driver's licenses, bank account/routing numbers, and medical/health insurance info. CPAP engaged forensic investigators, contained the threat, and offered one year of credit monitoring to affected individuals. Notification letters were mailed August 15, 2025.
- South Carolina State AGas victim2025-08-22
CPAP Medical Supplies and Services Inc. disclosed a cybersecurity incident where an unauthorized actor accessed its network. Access occurred between Dec 13-21, 2024; discovered June 27, 2025. Impacted data included names and PHI. The company engaged forensic investigators, contained the threat, and offered 12 months of credit monitoring. No specific affected count was provided in the notice.
- Washington State AGas victim2025-08-15
CPAP Medical Supplies and Services Inc reported a ransomware cyberattack affecting 1,381 Washington residents. The incident occurred between December 13 and 21, 2024. Data types included PII, government IDs, financial account numbers, and PHI. The company offered credit monitoring and notified the WA AG.
- Massachusetts State AGas victim2025-08-15
CPAP Medical Supplies and Services Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-08-15. 204 Massachusetts residents were affected.
- California State AGas victim2025-08-15
CPAP Medical Supplies and Services Inc. reported a data breach to the California Attorney General involving unauthorized access to personal information between December 13 and December 21, 2024. The incident potentially exposed protected health information (PHI), including medical records and insurance details, as well as personally identifiable information (PII) such as names, addresses, and Social Security numbers. The company is offering credit monitoring services to affected individuals. The specific cause of the breach and the number of affected individuals were not disclosed in the provided documents.
- FLORIDAHHS OCRas victim2025-08-15
CPAP Medical Supplies and Services Inc. (FL) reported to HHS OCR on 2025-08-15 a Hacking/IT Incident affecting 90,133 individuals. Breached information was located on a Network Server. No business associate was identified as present. No further details were provided in the web description.
- Nebraska State AGas victim2025-08-15
CPAP Medical Supplies and Services Inc notified Nebraska and other state residents of a data breach involving personal and financial information. The notification letter details steps for credit monitoring, fraud alerts, and security freezes. No specific discovery or occurrence dates were provided in the text.
- Maine State AGas victim2025-08-15
CPAP Medical Supplies and Services Inc. reported an external system breach (hacking) occurring on December 13, 2024, discovered on June 27, 2025. The incident affected 90,133 individuals nationwide, including 133 Maine residents. Compromised data included names, government IDs, financial account numbers, and health insurance information. The company notified affected individuals on August 15, 2025, and offered 24 months of credit monitoring.
- Illinois State AGas victim2025-08-01
CPAP MEDICAL SUPPLIES AND SERVICES INC. filed a data-breach notice with the Illinois Attorney General in August 2025 (case 25-08-371). The register records the breach as discovered on June 27, 2025. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.