Medical device logistics firm confirms a breach found months later

The Massachusetts device-logistics provider took seven months to confirm what data left its network after a December 2025 intrusion.

MedRisk Staff
By
2 Min Read

An intruder roamed the network of a Massachusetts medical device supply-chain firm for four days in December, and it took the company seven months to learn what had been taken. Millstone Medical Outsourcing, which handles post-manufacturing and logistics work for device makers, flagged suspicious activity on December 16, 2025, and forensics pinned the access window to December 15 through 19. A review completed July 15, 2026 finally established which records were at risk, and the company reported the matter to the Vermont attorney general on September 21.

Names, Social Security numbers, and health records were involved, according to a notice the company sent to USA Today. Attorneys are now investigating whether affected people can pursue a class action.

The delay is the notable part. Seven months passed between the intrusion and the company’s understanding of what data left the building, a gap that leaves patients blind to the risk while exposed credentials age.

Device makers lean on logistics and outsourced manufacturing partners for sterilization, packaging, and inventory. Those suppliers often sit outside a health system’s vendor inventory, yet they can hold the same identifiers. The case is a reminder for procurement and security teams to map the extended supply chain, not just the clinical IT stack.

Share This Article