ATHENAHEALTH, INC.
ent_019e105c1fe3442acdc9378ee45d81d5
Disclosures
7
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,974
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ATHENAHEALTH, INC.
- Normalized
- athenahealth— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493004JZ4RQIZBHP241
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- athenahealth.com
Disclosure history (7)newest first
- Massachusetts State AGas victim2024-11-16
athenahealth, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-11-16. 28 Massachusetts residents were affected.
- Montana State AGas victim2024-11-15
athenahealth, Inc. notified Montana residents of a data breach where Eligibility Transaction Files (containing names, addresses, DOB, gender, and clinical/payment info) were inadvertently uploaded to a publicly accessible internet repository due to a manual configuration error. The incident was discovered on September 16, 2024, after an insurance provider alerted athenahealth. No SSN or financial account numbers were involved. athenahealth removed the files, investigated, and offered 12 months of identity protection services.
- MASSACHUSETTSHHS OCRas victim2024-11-15
athenahealth, Inc. reported to HHS on 2024-11-15 an Unauthorized Access/Disclosure affecting 1,974 individuals. An employee posted PHI (names, addresses, DOBs, SSNs, insurance info) to the Internet. Breached information located on Network Server. Business associate present.
- New Hampshire State AGas victim2024-11-15
athenahealth, Inc. notified the NH AG of a data incident affecting one NH resident. On Sept 16, 2024, an insurance provider alerted athenahealth that Eligibility Transaction Files were visible in a public repository. Root cause was a manual configuration error; files uploaded on or after April 3, 2024. Data included demographic info. athenahealth removed files, investigated, notified HHS OCR and individuals, and offered 12 months of identity protection.
- Indiana State AGas victim2024-11-15
athenahealth Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-04-03 and was reported on 2024-11-15. 4 Indiana residents were affected. 1,974 individuals affected in total.
- Idaho State AGas victim2024-11-15
athenahealth, Inc. notified the Idaho Attorney General on November 15, 2024, of a cybersecurity incident affecting one Idaho resident. The incident involved the inadvertent upload of Eligibility Transaction Files to a publicly accessible internet repository due to a manual configuration error by an employee. The files contained demographic and clinical data (names, addresses, DOB, provider info) but no financial or SSN data. athenahealth removed the files, investigated, and provided 12 months of Experian IdentityWorks to the affected individual.
- Illinois State AGas victim2024-11-01
ATHENAHEALTH, INC. filed a data-breach notice with the Illinois Attorney General in November 2024 (case 24-11-030). The register records the breach as discovered on November 15, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.