RGH Enterprises, Inc.
ent_01793d2aed28a2f801387a80
Disclosures
5
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,572
nationwide · HHS OCR OH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- RGH Enterprises, Inc.
- Normalized
- rgh enterprises— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- CARDINAL HEALTH, INC.— per SEC Exhibit 21 filing
Disclosure history (5)newest first
- OHIOHHS OCRas victim2019-07-05
RGH Enterprises, Inc. d/b/a Edgepark Medical Supplies (OH) reported to HHS on 2019-07-05 a Hacking/IT Incident affecting 6,572 individuals. Breached ePHI was located on a Network Server and included names, dates of birth, addresses, health insurance information, and purchasing data. The CE implemented additional technical safeguards as mitigation and notified affected individuals, media, and posted a substitute notice on its website.
- Illinois State AGas victim2019-01-01
RGH ENTERPRISES, INC DBA. EDGEPARK MEDICAL SUPPLIES filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-248). The register records the breach as discovered on May 13, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OHIOHHS OCRas victim2018-01-22
RGH Enterprises, Inc. reported to HHS on January 22, 2018, that a spreadsheet formatting error led to mailings being sent to the wrong patients. This unauthorized disclosure of protected health information (PHI), including patient names, affected 4,586 individuals. The company has since implemented new quality assurance procedures, retrained the responsible employee, and notified those affected.
- OHIOHHS OCRas victim2014-01-13
Computer hackers installed malware on the covered entity's website that intercepted ePHI of approximately 4,230 individuals, including names, DOBs, contact details, partial payment-card data, primary physicians, diagnoses, order histories, and health insurer information. The entity removed the malware from affected servers and migrated the website to non-compromised infrastructure. Reported to HHS OCR on 2014-01-13.
- New Hampshire State AGas victim2014-01-10
RGH Enterprises, Inc. d/b/a Edgepark Medical Supplies notified the NH Attorney General of a security event affecting 26 NH residents. Hackers exploited a vulnerability in Adobe Coldfusion on the company's web server between March 9-11, 2013, installing malware that intercepted online account usernames and passwords. The malware was discovered on December 12, 2013. Affected data included names, dates of birth, addresses, phone numbers, email addresses, partial credit card information, and for one individual, full credit card numbers. Health information including diagnoses, primary physicians, and order history was also potentially accessible. The company removed the malware, reset passwords, and offered 12 months of identity protection.