Numotion, a mobility equipment provider, experienced two data incidents in 2024. The first occurred in March 2024 and involved unauthorized access to its systems. The second incident, a third-party phishing incident affecting Numotion’s email and user accounts, occurred on September 2, 2024, and was discovered on the same day. Numotion sent notices to affected individuals after both incidents, with the September incident notifications occurring by March 7, 2025.
The incidents exposed various data types. The March 2024 incident involved names, dates of birth, equipment order details, medical documentation, medical insurance information, and in some cases, Social Security numbers. The September 2024 incident exposed names, dates of birth, product information, payment and financial account information, health insurance information, medical information, and limited Social Security numbers. Public reporting indicates the September incident affected approximately 494,326 individuals, with HHS OCR figures citing up to 529,004 individuals.
Details surrounding the precise nature of some exposures and the exact number of individuals affected across all states continue to emerge. A class action settlement related to these incidents has been established.