AccidentalMisconfigurationCustomer Data InvolvedBusiness Associate (HIPAA)PIIIDENTITY_BASICLowContained
ATHENAHEALTH, INC.
bd_8ba652ba3e10c74b · schema v1 · pii pii-v1
Full breach record for ATHENAHEALTH, INC. →athenahealth, Inc. notified the NH AG of a data incident affecting one NH resident. On Sept 16, 2024, an insurance provider alerted athenahealth that Eligibility Transaction Files were visible in a public repository. Root cause was a manual configuration error; files uploaded on or after April 3, 2024. Data included demographic info. athenahealth removed files, investigated, notified HHS OCR and individuals, and offered 12 months of identity protection.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4578d2cfe6b20643Montana State AGfiled 2024-11-15Candidate
- bd_dda00b7398f09ba5Indiana State AGfiled 2024-11-15Verified
- bd_e9e06934e266ff55Idaho State AGfiled 2024-11-15Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/athenahealth-20241115.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2024
- Raw hash
- 5b35c708e66b87165ea9f9174e22c280aec44fa9752e1758660d0fc53696c19e
Reporting entity
- Name
- ATHENAHEALTH, INC.norm: athenahealth
- Domain
- athenahealth.com
Victim entity
- Name
- ATHENAHEALTH, INC.norm: athenahealth
- Domain
- athenahealth.com
Incident
- Discovered
- Sep 16, 2024
- Materiality determined
- —
- Notification sent
- Nov 15, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1119 Automated Collection
- Regulator citations
- Notified HHS Office for Civil Rights
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.