Cogent Healthcare, Inc.
bd_0df37bcbda25eaee · schema v1 · pii pii-v1
Full breach record for Cogent Healthcare, Inc. →3 incidents on fileCogent Healthcare, Inc. disclosed a security lapse involving its third-party vendor, M2ComSys, a medical transcription company. Between May 5, 2013, and June 24, 2013, protected health information (PHI) including patient names, dates of birth, diagnoses, and treatment summaries was accessible via an insecure internet site. Cogent discovered the lapse on June 24, 2013, and immediately contained the access. The company ended its relationship with M2, secured the hardware, and confirmed removal of indexed data from Google. No Social Security numbers were involved.
J jump to incidentP pin to compareR raw source
Incident timeline
May 5, 2013
Begins
Jun 24, 2013
Discovered
Aug 8, 2013
Filed
vs. sector median
6 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.