Compumedics Neuroscan
bd_c5f48e94e925d457 · schema v1 · pii pii-v1
Full breach record for Compumedics Neuroscan →Compumedics USA, Inc. reported to HHS on 2025-06-27 a Hacking/IT Incident affecting 318,150 individuals. Breached information located on Network Server. The business associate experienced a hacking incident on its network server containing the protected health information (PHI) of 318,150 individuals. The PHI involved in the breach included names, addresses, birthdates, Social Security numbers, diagnoses/conditions, lab results, and medications. The BA notified affected covered entities of the breach and provided breach notification to individuals on behalf of the affected covered entities. In response to the breach, the BA implemented additional administrative, technical, and security safeguards.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_02b2d050be85a57eMontana State AGfiled 2025-06-27Verified
- bd_983bf92379893f31New Hampshire State AGfiled 2025-06-27Verified
- bd_16b3e3880a9dac3cTexas State AGfiled 2025-07-01(4d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 27, 2025
- Raw hash
- c48e62746dd85bc4835a56c5544d1ee001928c40b6e2fa3757964edf35e8000e
Source filing
Reporting entity
- Name
- Compumedics Neuroscannorm: compumedics neuroscan
- Domain
- compumedicsneuroscan.com
- Industry
- Health Care Services
Victim entity
- Name
- Compumedics Neuroscannorm: compumedics neuroscan
- Domain
- compumedicsneuroscan.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 318,150
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported to HHS
- Third party
- via Compumedics USA, Inc.business associate
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.