Medtronic
ent_7939d258b75dbf360605bc84
Disclosures
11
State AG · SEC 8-K · HHS OCR · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
3,834,294
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Medtronic
- Normalized
- medtronic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- D56MRZY2INAN94ZONZ37
- SEC EDGAR CIK
- 0001613103
- Domain
- medtronic.com
Disclosure history (11)newest first
- California State AGas victim2026-06-29
Medtronic Inc. reported a cybersecurity incident where an unauthorized actor accessed corporate IT systems from April 13-19, 2026. Medtronic became aware of unusual activity on April 15, 2026. Affected data includes names, contact info, dates of birth, Social Security numbers, and health-related information for patients with Medtronic devices. The company engaged third-party cybersecurity experts, notified law enforcement and regulators, and is offering 24 months of credit and identity monitoring services. No evidence suggests data was publicly posted.
- New Hampshire State AGas victim2026-06-29
Medtronic Inc. notified the New Hampshire Attorney General on June 29, 2026, of a cybersecurity incident occurring between April 13 and 19, 2026. An unauthorized actor accessed corporate IT systems, potentially exposing personal information of 12,215 New Hampshire residents, including names, contact info, DOB, SSN, and health-related data. Medtronic engaged third-party cybersecurity experts, notified law enforcement and consumer reporting agencies, and offered 24 months of credit monitoring and identity theft restoration services. Device safety was not impacted.
- Massachusetts State AGas victim2026-06-29
Medtronic Inc. filed a breach notification with the Massachusetts Attorney General regarding a cybersecurity incident involving personal information. The company is offering 24 months of complimentary credit monitoring, dark web monitoring, and identity theft restoration services through Epiq to affected individuals. The notice provides guidance on placing security freezes and fraud alerts with credit bureaus.
- Nebraska State AGas victim2026-06-29
Medtronic Inc. disclosed a cybersecurity incident affecting approximately 12,054 individuals, primarily in Nebraska and Rhode Island. Unauthorized access occurred between April 13-19, 2026, impacting patient data including names, SSNs, DOBs, and health information. Medtronic engaged third-party experts and law enforcement, offering 24 months of credit and identity monitoring.
- Indiana State AGas victim2026-06-29
Medtronic Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2026-04-13 and was reported on 2026-06-29. 90,889 Indiana residents were affected. 3,834,294 individuals affected in total.
- Oregon State AGas victim2026-06-29
Medtronic Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-06-29. The breach occurred during 4/13/2026 - 4/19/2026. The breach was discovered on 4/15/2026. 3,834,294 individuals were affected. Notice was sent on 6/29/2026.
- Delaware State AGas victim2026-06-29
Medtronic Inc. disclosed a cybersecurity incident affecting Rhode Island residents. Unauthorized actors accessed corporate IT systems between April 13 and 19, 2026. Impacted data included names, contact info, DOB, SSN, and health-related information. Medtronic engaged third-party cybersecurity experts, worked with law enforcement, and offered 24 months of credit monitoring and identity theft restoration via Epiq. The incident did not affect device safety.
- FEDERALSEC 8-Kas victim2026-04-27
Medtronic plc filed an 8-K on April 24, 2026, disclosing that an unauthorized third party accessed certain IT systems. The company contained the incident, activated response protocols, and engaged external experts. No impact to patient safety or operations was identified, and no material financial impact is expected.
- FEDERALSEC 8-Kas victim2026-04-27
MiniMed Group, Inc. (a subsidiary of Medtronic plc) filed an 8-K on April 27, 2026, reporting a cybersecurity incident affecting Medtronic's IT systems. Medtronic engaged external experts and contained the incident. MiniMed stated it was not aware of any compromise to its own IT systems and did not expect a material impact on its business or financial results.
- Montana State AGas victim2016-07-08
Medtronic notified Montana residents of a data breach involving the MiniMed Ambassador Program. Personal information, including names, addresses, and healthcare provider names, was inadvertently accessible on the internet due to a storage misconfiguration. Medtronic offered one year of credit monitoring through ID Experts.
- MINNESOTAHHS OCRas victim2013-07-10
Medtronic, Inc. reported to HHS on 2013-07-10 a Theft affecting 2764 individuals. Breached information located on Paper/Films. The covered entity misplaced a box of paper records containing patient pump training records, patient names, device serial numbers, phone numbers, email addresses, and potentially social security numbers and medical records.
Subsidiary disclosures (2)filed by group companies
◈ These filings were made by or about subsidiaries of Medtronic — not by Medtronic itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia MEDTRONIC MINIMED, INC.2018-11-26
Medtronic Minimed notified the NH Attorney General of an insider incident on Oct 11, 2018, where an employee improperly recorded sensitive customer info. 12 NH residents affected. Data included PHI, SSN, credit card info. Employee terminated, law enforcement notified, credit monitoring offered.
- Montana State AGvia MEDTRONIC MINIMED, INC.2018-11-21
Medtronic notified customers that an employee improperly recorded sensitive personal information (name, address, DOB, SSN, credit card data) of at least two known customers and potentially others. The employee was terminated. Medtronic offered 24 months of credit monitoring and notified HHS and state agencies. Incident discovered Oct 11, 2018.