ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Medical device manufacturer ERMI discloses data security incident affecting nearly 75,000

American medical device manufacturer Ermi announced that a data security incident discovered last year compromised the sensitive personal information of nearly 75,000 people.

 

Headquartered in Atlanta, Georgia, Ermi is a medical device manufacturer that develops non-invasive rehabilitation devices to improve joint mobility and support recovery following orthopedic injuries and surgeries. Its products are used by healthcare providers across the United States to help patients regain mobility and function during home-based recovery.

 

In a data security incident notice published on its website, Ermi said that last year it identified unauthorised access to its internal network. The medical device company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.

 

“Following the completion of the investigation, it was determined that some files may have been accessed or removed by the unauthorised individual between February 15, 2025 and August 14, 2025,” Ermi said.

 

The compromised data included names, Social Security numbers, driver’s license numbers, Veteran identification numbers, passport numbers, usernames and passwords, email addresses with passwords, security questions, dates of birth, dates of death, taxpayer/employer identification numbers, financial account information, payment card information, medical information, and health insurance information.

 

In a filing with the U.S. Department of Health and Human Services, Ermi said it has identified at least 74,074 individuals impacted by the incident.

 

The medical device company has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. 

 

It has also offered complimentary identity protection and credit monitoring services to all affected individuals.

 

At the time of publishing, no known hacker group claimed responsibility for the cyber attack on Ermi. The medical device manufacturer also did not share details on who was behind the attack, how much data was compromised, or whether it had received a ransom demand.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543