Skip to content

ZOLL Services

Disclosed Mar 18, 20197 years ago277,319 affectedConfirmed

Official notice

Sonian, a subcontractor of the covered entity’s (CE) business associate (BA), Apptix, left a computer server port open during a data migration, causing a breach of 277,319 individuals’ protected health information. The types of PHI involved included names, addresses, dates of birth, medical information, and in some instances, social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. It also reported the incident to law enforcement. Following the breach, the CE obtained written assurances from Sonian that it implemented technical safeguards to limit the risk of such incidents in the future, and it ensured that Sonian retrained its staff. OCR reviewed the CE’s BA agreement.

What is known

People affected277,319 (as reported by the organization)
DisclosedMar 18, 2019
HappenedNov 8, 2018
AttackHacking
Data exposedNames, Social Security numbers, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: ZOLL Servicesoag.ca.gov · Official notice
Oregon DOJ breach notice: ZOLL Servicesjustice.oregon.gov · Official notice
Indiana Attorney General 2019 data breach report: Zoll Servicesin.gov · Official notice
Maine Attorney General breach notice archive: ZOLL Servicesmaine.gov · Official notice
HHS OCR breach report (archive, resolved): ZOLL Services (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INMar 18, 201991
HHS archivetotalMar 18, 2019277,319
California AGresidents of CAApr 4, 2019
Oregon DOJresidents of ORJun 6, 2019277,319
Maine AGresidents of MEJun 13, 201911

Other breaches at ZOLL Services

BreachAffected
Disclosed Mar 10, 2023Mar 10, 20233 years agoHacking997K
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
  • 2026-09-25 · summary: empty to Sonian, a subcontractor of the covered entity’s (CE) business associate (BA), Apptix, left a computer server port open during a data migration, causing a breach of 277,319 individuals’ protected health information. The types of PHI involved · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 277319 · backfill source
  • 2026-09-25 · disclosed: 2019-04-04 to 2019-03-18 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about ZOLL Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.