FEDERALHackingHealthcareHealthcareMisconfigurationBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedData PublishedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIHighResolved
Med-Cert, Inc.
bd_7c838ee73a0b1cf4 · schema v1 · pii pii-v1
Full breach record for Med-Cert, Inc. →Med-Cert, Inc. reported to HHS on 2017-09-02 a Hacking/IT Incident affecting 7,253 individuals. The breach was caused by a subcontractor, Alentus Hosting, which failed to reactivate a firewall after a software update, allowing web-crawlers to access and post protected health information (PHI) online. The exposed data, located on a Network Server and Other systems, included names, addresses, birthdates, Social Security numbers, and case management reports. The information was later removed from public access.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,253 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 2, 2017
- Raw hash
- 47059bdb6726cd5842ea27006985ace5ad938a364b43c6e073e71d13ffc9217a
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Med-Cert, Inc.norm: med cert
- Industry
- Business Associate
Victim entity
- Name
- Med-Cert, Inc.norm: med cert
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Jul 7, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 7,253
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- Threat actor
- Partner
- Regulator citations
- OCR provided technical assistance to the BA regarding the BA agreement requirements of HIPAAObtained written assurances that the BA implemented the corrective actions
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 7, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.