Inmediata Health Group
bd_f12cfc9ad2964857 · schema v1 · pii pii-v1
Full breach record for Inmediata Health Group →Inmediata Health Group, LLC (Healthcare Clearing House) reported to HHS OCR on 2019-05-07 an Unauthorized Access/Disclosure affecting 1,565,338 individuals. PHI — including patient names, dates of birth, home addresses, Social Security numbers, claims information, and diagnosis/treatment data — was left publicly accessible on a Network Server and indexed by internet search engines from May 2016 through January 2019. OCR found failures in risk analysis and system-activity monitoring. Inmediata paid a $250,000 settlement; a separate 33-state AG settlement addressed corrective actions.
J jump to incidentP pin to compareR raw source
Incident timeline
May 1, 2016
Begins
Jan 1, 2018
Discovered
May 7, 2019
Filed
vs. sector median
+58 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- California State AGbd_07367e77ebb862962019-04-30 · +7dVerified
- Montana State AGbd_a3280d85edb477072019-04-30 · +7dCandidate
- Oregon State AGbd_6002e6858d8b16ca2019-06-03 · +27dVerified
- HHS OCR enforcementbd_b591e1e63f897fff2024-12-10 · +2044dVerified by operator
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Apr 30 (CA), last Dec 10 — a 2051-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.