
Illinois-based Medical Express Ambulance Inc. said the data security incident it suffered last year compromised the sensitive personal information of more than 118,000 individuals.
In a data security incident notice posted on its website, Medical Express Ambulance, doing business as MedEx Ambulance, said that on March 18, 2024, it experienced a network disruption that impacted certain internal systems.
The ambulance service provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. MedEx also took the affected systems offline and notified relevant law enforcement authorities about the incident.
“The forensic investigation determined that personal information may have been acquired by the threat actor. Based on these findings, MedEx decided to proceed with an analysis of the compromised data for any potential sensitive personal information (“PII”) or protected health information (“PHI”),” reads the notice.
The compromised data included names, dates of birth, demographic information, Social Security numbers, driver’s license numbers, state identification numbers, medical information, financial information, health insurance information, usernames and password, passport information.
The incident was reported to the Office of the Maine Attorney General where MedEx said that it identified at least 118,418 individuals who were impacted by the incident.
“Since the discovery of the Incident, MedEx moved quickly to investigate, respond, and confirm the security of our systems,” the company said. “Additionally, MedEx took the following steps, including, but not limited to: disconnecting all access to the network; implementing an organisation-wide credential reset of all users; restructured and enhanced security systems, and implementing updated data management software.”
MedEx has urged all affected individuals to remain vigilant and monitor their credit reports and financial statements for any suspicious activities and to report suspicious activities to relevant law enforcement authorities and their banks.
It has also offered one year of complimentary credit monitoring and identity theft protection services via HaystackID to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on MedEx. The ambulance service provider also did not share details on who was behind the attack or whether it has received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543