Cogent Healthcare, Inc.
bd_0df37bcbda25eaee · schema v1 · pii pii-v1
Full breach record for Cogent Healthcare, Inc. →Cogent Healthcare, Inc. disclosed a security lapse involving third-party vendor M2ComSys, a medical transcription company. Between May 5, 2013, and June 24, 2013, unauthorized parties accessed patient care notes containing PHI, including patient names, DOBs, diagnoses, and medical record numbers. No Social Security numbers or copies of medical records were included. Cogent ended its relationship with M2, recovered hardware, and worked with Google to remove indexed PHI. Affected individuals were offered one year of Experian’s ProtectMyID credit monitoring and fraud resolution services.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-42430
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2013
- Raw hash
- 73e325ed45b9ed2eb818fd95245d20c639b4a999f53d4c9f110ed9bb521b1f20
Reporting entity
- Name
- Cogent Healthcare, Inc.norm: cogent healthcare
Victim entity
- Name
- Cogent Healthcare, Inc.norm: cogent healthcare
Incident
- Discovered
- Jun 24, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Third party
- via M2ComSys (M2)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.