MedEvolve, a healthcare billing services provider, disclosed a data breach affecting 15 patients. On March 29, 2018, an FTP server containing patient data was inadvertently made accessible to the internet. The breach exposed names, billing addresses, phone numbers, health insurer details, account numbers, and Social Security numbers. The exposure lasted until May 4, 2018, when unauthorized access occurred. A screenshot of the data was posted online. MedEvolve engaged forensic investigators, secured the portal, and notified HHS, media, and state regulators. Affected individuals received two years of complimentary credit monitoring.
Affected (this filing): 15