ATHENAHEALTH, INC.
bd_e9e06934e266ff55 · schema v1 · pii pii-v1
Full breach record for ATHENAHEALTH, INC. →athenahealth, Inc. notified the Idaho Attorney General on November 15, 2024, of a cybersecurity incident affecting one Idaho resident. The incident involved the inadvertent upload of Eligibility Transaction Files to a publicly accessible internet repository due to a manual configuration error by an employee. The files contained demographic and clinical data (names, addresses, DOB, provider info) but no financial or SSN data. athenahealth removed the files, investigated, and provided 12 months of Experian IdentityWorks to the affected individual.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 3, 2024
Begins
Sep 16, 2024
Discovered
Nov 15, 2024
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_4578d2cfe6b206432024-11-15Verified
- HHS OCRbd_835a237069fb82112024-11-15Verified
- New Hampshire State AGbd_8ba652ba3e10c74b2024-11-15Verified
- Indiana State AGbd_dda00b7398f09ba52024-11-15Verified
Show 2 more filings ↓Show fewer ↑up to 14d gap
- Massachusetts State AGbd_0ce80a8b77ec1d4a2024-11-16 · +1dVerified
- Illinois State AGbd_47ff2c4a38b2128f2024-11-01 · +14dVerified
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Nov 1 (IL), last Nov 16 (MA) — a 15-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.