Clustered 5 filings across 4 jurisdictions · filing window Feb 23, 2024 → May 29, 2024. View entity profile → Other incidents for this victim →
incident inc_4e619398fde0423e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA IN ME MT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Dec 20, 2023 → Dec 26, 2023
When the intrusion reportedly occurred, per the linked filings
Dec 26, 2023
Reported by CALIFORNIA AG, MAINE AG filings
medQ, Inc. experienced a ransomware incident where files were encrypted and copied by an unauthorized actor between December 20 and December 26, 2023. The breach affected PHI, including names, SSNs, driver's license numbers, diagnoses, and lab results. medQ disconnected the network, engaged forensic investigators, and offered 12 months of credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
medQ, Inc. experienced a ransomware incident where files were encrypted and exfiltrated from its software platform hosted by a third-party data center between December 20-26, 2023. The breach affected individuals' PHI, including names, SSNs, driver's license numbers, diagnoses, and treatment information. medQ disconnected the network, engaged forensic investigators, and is offering 12 months of credit monitoring.
medQ, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-12-20 and was reported on 2024-02-23. 12 Indiana residents were affected. 54,353 individuals affected in total.
Affected (this filing): 54,353
medQ, Inc., a healthcare technology company, experienced an external system breach that affected 54,353 individuals. The incident occurred between December 20, 2023, and December 26, 2023, and was discovered on the final day. Affected individuals were notified on February 23, 2024, and offered 12 months of credit monitoring services.
Affected (this filing): 54,353
medQ, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2024-02-23. The breach occurred from 12/20/2023 to 12/26/2023. 4 Montana residents were affected.
Affected (this filing): 4