Medtronic’s April cybersecurity incident affected more than 72,000 residents of Massachusetts and Vermont, with Social Security numbers and health records among the data exposed, state attorney general breach notification filings show.
Massachusetts recorded 63,534 residents affected — with both SSNs and medical records compromised — in a state breach notification filing dated June 29. Vermont’s attorney general recorded 8,668 residents with SSNs and health records exposed in a separate filing dated June 28. The two figures represent only a portion of the total affected population.
In a June 29 update and a statement to Becker’s, Medtronic said it has begun notifying affected individuals and is offering 24 months of complimentary credit monitoring, dark web monitoring, and identity theft restoration services. Medtronic said it has found no evidence that impacted information has been publicly posted or exposed online, and reiterated that the incident did not affect the security or function of any Medtronic device.
The company said it has implemented additional safeguards and continues to work with third-party cybersecurity experts to strengthen its systems. Corporate IT networks remain separate from those supporting Medtronic’s products, manufacturing operations, and hospital customers.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.