Skip to content

MedWatch

Disclosed Apr 27, 20188 years ago40,621 affectedConfirmed

Official notice

On October 20, 2017, an information technology subcontractor for MedWatch, a business associate (BA), applied a misconfigured security patch to an online portal during a routine update causing some protected health information (PHI) to be viewable by the public. The breach affected 40,621 individuals who are members of the BA’s client health plans and third party administrators. The exposed PHI included various combinations of members’ demographic and health insurance information. Upon discovery of the breach on December 15, 2017, the BA immediately restricted access to the portal and requested that internet search engines remove all cached data. The BA notified its client covered entities and provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. The BA improved technical safeguards, updated its policies, and retrained all staff and contractors on HIPAA Privacy and Security. OCR obtained assurances that the BA implemented the corrective actions listed above.

What is known

People affected40,621 (as reported to HHS)
DisclosedApr 27, 2018
HappenedOct 20, 2017
AttackInsider
Data exposedNames, Social Security numbers, Names
SectorHealthcare · US
StatusConfirmed

Sources

Source
Maine Attorney General breach notice archive: MedWatchmaine.gov · Official notice
HHS OCR breach report (archive, resolved): MedWatch (Business Associate, FL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Maine AGresidents of MEApr 27, 20183
HHS archivetotalApr 27, 201840,621
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 40621 · backfill source
  • 2026-09-25 · summary: empty to On October 20, 2017, an information technology subcontractor for MedWatch, a business associate (BA), applied a misconfigured security patch to an online portal during a routine update causing some protected health information (PHI) to be v · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.

Everything about MedWatch

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.