IMX Medical Management Services
ent_79f0ad1d4e9548943ca22d99
Disclosures
5
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
3
as filed · State AG MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- IMX Medical Management Services
- Normalized
- imx medical management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2023-07-27
IMX Medical Management Services, Inc. discovered malware on a laptop in September 2022, with indicators possibly dating to June 2022. A threat actor accessed email bodies and server folders containing PHI and PII for claimants, employees, and providers through October 2022. IMX took systems offline, engaged forensics, notified law enforcement, and migrated to a new network operated by parent company QTC. No evidence of exfiltration was confirmed, but access to email bodies occurred.
- 🦬Montana State AGas victim2023-07-27
IMX Medical Management Services reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-27. The breach occurred from 6/1/2022 to 9/1/2022. 3 Montana residents were affected.
- 💎Delaware State AGas victim2023-07-27
IMX Medical Management Services, Inc. disclosed a security incident discovered on September 1, 2022, involving malware on a single laptop as early as June 2022. A threat actor gained access to IMX systems through October 2022. The incident potentially exposed personal and protected health information of employees, providers, and claimants. IMX took systems offline, engaged in forensic investigation, notified law enforcement, and migrated operations to a new QTC-operated network. Affected individuals were offered two years of credit monitoring.
- 🍁Vermont State AGas victim2023-07-27
IMX Medical Management Services, Inc. disclosed a security incident discovered on September 1, 2022, involving malware on a laptop as early as June 2022. The threat actor accessed certain IMX systems and devices through October 2022, gaining access to email bodies and server folders containing personal and protected health information of claimants. IMX took systems offline, engaged in forensic investigation, and notified law enforcement. The company established a new network via parent company QTC Management, Inc., and offered two years of credit monitoring to affected individuals.
- 🦞Maine State AGas victim2023-07-12
IMX Medical Management Services reported an external system breach that occurred between June 2022 and October 26, 2022. The breach, discovered on September 1, 2022, affected three Maine residents. The compromised information included names and driver's license or non-driver identification card numbers. IMX offered 24 months of complimentary credit monitoring and identity protection services through Equifax to those affected.