DisclosureLens
AccidentalHealthcareHealthcareMisconfigurationSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPHIHealth (basic)Identity (basic)LowContained

Cogent Healthcare, Inc.

bd_0df37bcbda25eaee · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 24, 2013

Filed

Aug 8, 2013

To disclose

6 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Cogent Healthcare, Inc.3 incidents on file

Cogent Healthcare, Inc. disclosed a security lapse involving its third-party vendor, M2ComSys, a medical transcription company. Between May 5, 2013, and June 24, 2013, protected health information (PHI) including patient names, dates of birth, diagnoses, and treatment summaries was accessible via an insecure internet site. Cogent discovered the lapse on June 24, 2013, and immediately contained the access. The company ended its relationship with M2, secured the hardware, and confirmed removal of indexed data from Google. No Social Security numbers were involved.

Incident timeline

undetected · 50 days
discovery → filing · 6 weeks / 45 days

May 5, 2013

Begins

Jun 24, 2013

Discovered

Aug 8, 2013

Filed

vs. sector median

6 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.