Orchard Medical Consulting
ent_852c7aa71aa93a54df048d1f
Disclosures
4
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,437
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Orchard Medical Consulting
- Normalized
- orchard medical consulting— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Indiana State AGas victim2020-07-01
Orchard Medical Consulting reported a data breach to the Indiana Attorney General. The breach occurred on 2020-01-16 and was reported on 2020-07-01. 1 Indiana residents were affected. 2,437 individuals affected in total.
- California State AGas victim2020-05-28
Orchard Medical Consulting disclosed that an unauthorized individual gained access to a single employee's email account on January 16, 2020, which was discovered on January 30, 2020. The incident potentially exposed personal information, including names, dates of birth, Social Security numbers, and limited medical information (PHI) such as diagnoses and treatment plans. The company contained the incident, reported it to regulators, and offered one year of credit monitoring to affected individuals. Remediation steps included implementing multi-factor authentication and forcing password changes.
- Montana State AGas victim2020-05-05
Orchard Medical Consulting notified Montana residents of a January 30, 2020 incident where an unauthorized individual accessed an employee's email account. Personal information, including PHI, SSNs, and DOBs, may have been accessed. The company implemented MFA, forced password changes, and offered one year of credit monitoring.
- California State AGas victim2020-05-05
Orchard Medical Consulting reported that an unauthorized individual gained access to a single employee's email account on January 16, 2020, which was discovered on January 30, 2020. The incident potentially exposed personal information including names, dates of birth, Social Security numbers, and limited medical information (diagnosis, treatment plan, health history). The company contained the incident, reset credentials, implemented MFA, and offered one year of credit monitoring.