HackingHealthcareTechnologyHealthcareCustomer Data InvolvedBusiness Associate (HIPAA)Delayed DiscoveryPIIPHIIDENTITY_BASICMINORMediumContained
FastHealth Corporation
bd_99d8cf94ee6bff7f · schema v1 · pii pii-v1
Full breach record for FastHealth Corporation →FastHealth Corporation, a contracted healthcare IT vendor providing operational and website services to hospital clients, suffered unauthorized access to its web server in mid-August 2017. The breach was reported by law enforcement on November 2, 2017. A forensic investigation confirmed an unauthorized third party may have acquired data from certain databases. Data review was completed January 26, 2018. Affected parties included minors. Kroll identity monitoring was offered. The company implemented new encryption and strengthened security protocols.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2dcab2d038f89ca3HHS OCRfiled 2018-02-27Verified
- bd_443fc3fc90bc52bdMontana State AGfiled 2018-02-27Verified
- bd_54159cba1053fb1dWashington State AGfiled 2018-02-27Verified
- bd_60a50c8ffb21c599Oregon State AGfiled 2018-02-27Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134095
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2018
- Raw hash
- 67e46dfb0769eb6d8f53078e31d794ab0b9365a4a55b1f6c5a2bc23b8406d141
Reporting entity
- Name
- FastHealth Corporationnorm: fasthealth
- Domain
- fasthealthcorporation.com
Victim entity
- Name
- FastHealth Corporationnorm: fasthealth
- Domain
- fasthealthcorporation.com
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Feb 1, 2018
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1530 Data from Cloud Storage Object
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.