United Seating and Mobility Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
United Seating and Mobility notified the Oregon Attorney General of a data breach affecting 698,577 people, with the notice made public on July 17, 2024. Individuals should review the notice to determine if their personal information was involved and take any recommended protective steps.
Nearly 700,000 people may have had personal information involved when United Seating and Mobility reported a data breach to Oregon authorities. For anyone who has done business with the company—customers, patients, or others whose details sit in its systems—the practical question is straightforward: what is known, what remains unclear, and what steps make sense next.
United Seating and Mobility notified Oregon residents of the incident in a filing reported to the Oregon Department of Justice on July 17, 2024. The notice identifies personal information as exposed and lists 698,577 people affected. Public detail beyond that filing is limited.
What happened
According to the breach notice filed with the Oregon Attorney General, United Seating and Mobility experienced a data breach and formally notified Oregon residents. The report is dated July 17, 2024. The filing states that 698,577 people were affected and that personal information was involved, as described in the breach notification.
The public record does not describe how the incident was discovered, whether systems were accessed by an unauthorized party, how long any intrusion lasted, or what technical method was used. Timing of the underlying event, beyond the July 17, 2024 reporting date, is not detailed in the available notice summary. Scale is given as the 698,577 figure; no further breakdown by state or customer category appears in the facts provided.
How a breach like this happens
Incidents that lead to notices of this kind often begin with common paths of unauthorized access. Attackers may obtain valid credentials through phishing, reuse of leaked passwords, or malware on an employee device. In other cases, a vulnerable internet-facing system, misconfigured cloud storage, or an unpatched application allows entry. Once inside, data may be copied, encrypted for ransom, or both.
Organizations that hold customer or patient records typically store identity details, contact information, and sometimes health- or equipment-related data in databases and document systems. When those repositories are reached, the result is often a notification that “personal information” was involved, even when the exact fields are not fully listed in every public filing. No specific threat group is named in connection with this notice, and none should be assumed.
Detection can take days or months. Companies then assess what was accessed, identify affected individuals, and file required notices with state attorneys general. The Oregon filing is one such step; it does not by itself prove negligence or establish every technical detail of the event.
United Seating and Mobility and its sector
United Seating and Mobility operates in the durable medical equipment and mobility sector. Firms of this type supply wheelchairs, seating systems, and related products and services to people with mobility needs. They routinely interact with patients, caregivers, clinicians, and insurers, and therefore maintain records that support ordering, fitting, billing, and ongoing support.
In that sector, typical holdings include names, addresses, phone numbers, dates of birth, insurance or billing identifiers, and information tied to medical equipment prescriptions or diagnoses. Some records may also include Social Security numbers or other government identifiers when required for eligibility or payment. A breach affecting such an organization is consequential because the data is often long-lived, linked to health circumstances, and useful for identity theft or targeted fraud. The July 2024 Oregon notice places this company among those that have had to tell regulators and residents that personal information was involved at significant scale.
What was likely exposed
The breach notification names personal information as exposed. It does not, in the facts available here, list every data element field by field. Exact contents therefore remain unconfirmed beyond that general category.
Organizations that provide seating and mobility equipment commonly hold identity and contact data, order and service history, and information needed for insurance or clinical coordination. Whether any given individual’s file included financial account numbers, full medical detail, or government ID numbers is not established by the public summary. Readers should treat the exposed set as “personal information” as stated in the notice, and not assume more specific categories without further official clarification from the company or regulators.
Why it matters
For affected people, the main risks are identity misuse and fraud. Personal information can be combined with other leaked data to open accounts, file false claims, or impersonate someone when dealing with insurers or government agencies. Because mobility and medical-equipment records can reflect health status or disability, there is also a privacy impact that goes beyond pure financial loss.
For the organization, a breach of this size means notification costs, possible regulatory follow-up, and the need to support people who ask about their own records. Trust with customers and clinical partners can be strained even when the full technical story is still incomplete. The 698,577 figure indicates a large population that may need to monitor accounts and official mail for unusual activity over an extended period.
None of this requires assuming the company was uniquely careless; it does require treating the notice as a real signal that personal data left the expected control boundary.
What to do if you're exposed
If you have been a customer or otherwise dealt with United Seating and Mobility, watch for the official notice letter or email and keep it. Review bank, credit-card, and insurance statements for unfamiliar activity. Consider placing a free fraud alert or credit freeze with the major credit bureaus if you are concerned about new-account fraud. Change passwords on related accounts and enable multi-factor authentication where available. Be cautious of follow-up calls or messages that claim to “verify” your data after a breach; scammers often exploit public notices.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets. That check does not replace official notices from United Seating and Mobility, but it can help you see whether your email is circulating more widely and prioritize further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stiiizy Inc. Data Breach Notice (Oregon Attorney General)American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.