MedWatch
Disclosed Apr 27, 20188 years ago40,621 affectedConfirmed
On October 20, 2017, an information technology subcontractor for MedWatch, a business associate (BA), applied a misconfigured security patch to an online portal during a routine update causing some protected health information (PHI) to be viewable by the public. The breach affected 40,621 individuals who are members of the BA’s client health plans and third party administrators. The exposed PHI included various combinations of members’ demographic and health insurance information. Upon discovery of the breach on December 15, 2017, the BA immediately restricted access to the portal and requested that internet search engines remove all cached data. The BA notified its client covered entities and provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. The BA improved technical safeguards, updated its policies, and retrained all staff and contractors on HIPAA Privacy and Security. OCR obtained assurances that the BA implemented the corrective actions listed above.
What is known
| People affected | 40,621 (as reported to HHS) |
|---|---|
| Disclosed | Apr 27, 2018 |
| Happened | Oct 20, 2017 |
| Attack | Insider |
| Data exposed | Names, Social Security numbers, Names |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Maine Attorney General breach notice archive: MedWatchmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): MedWatch (Business Associate, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Maine AGresidents of ME | Apr 27, 2018 | 3 |
| HHS archivetotal | Apr 27, 2018 | 40,621 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 40621 · backfill source
- 2026-09-25 · summary: empty to On October 20, 2017, an information technology subcontractor for MedWatch, a business associate (BA), applied a misconfigured security patch to an online portal during a routine update causing some protected health information (PHI) to be v · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.