Inmediata Health Group
bd_f12cfc9ad2964857 · schema v1 · pii pii-v1
Full breach record for Inmediata Health Group →Inmediata Health Group, LLC (Healthcare Clearing House) reported to HHS OCR on 2019-05-07 an Unauthorized Access/Disclosure affecting 1,565,338 individuals. PHI — including patient names, dates of birth, home addresses, Social Security numbers, claims information, and diagnosis/treatment data — was left publicly accessible on a Network Server and indexed by internet search engines from May 2016 through January 2019. OCR found failures in risk analysis and system-activity monitoring. Inmediata paid a $250,000 settlement; a separate 33-state AG settlement addressed corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 7, 2019
- Raw hash
- 56cf9ff2c87617d81b232c294fcce02004a7e51d5b2cbb96ee58c4d83636bd14
Source filing
Reporting entity
- Name
- Inmediata Health Groupnorm: inmediata health
- Industry
- Health Care Services
Victim entity
- Name
- Inmediata Health Groupnorm: inmediata health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 1, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,565,338
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage
- Regulator citations
- HHS OCR investigation opened 2018 following complaintSettlement reached with HHS OCR: $250,000 paidSeparate settlement with 33 state attorneys general including corrective action plan
Compliance
- Time to disclose
- 16 months(491 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 1, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.