Cardiovascular Associates Holdings, LP
ent_019e2322a4dde9499ea2bc3ec53b7863
Disclosures
10
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
441,640
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cardiovascular Associates Holdings, LP
- Normalized
- cardiovascular associates— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900TG3BP1UB23R619
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Indiana State AGas victim2023-03-17
Cardiovascular Associates reported a data breach to the Indiana Attorney General. The breach occurred on 2022-11-28 and was reported on 2023-03-17. 42 Indiana residents were affected. 441,640 individuals affected in total.
- California State AGas victim2023-03-17
Cardiovascular Associates, a cardiology practice in Birmingham, Alabama, disclosed a data security incident where an unauthorized third party accessed systems and exfiltrated data between November 28, 2022, and December 5, 2022. Affected individuals include current or former employees and affiliated medical practice staff. Compromised data included names, dates of birth, addresses, Social Security numbers, passport/driver's license numbers, and financial account information. Health/medical information was not involved. The organization engaged a forensic firm, restricted access, and is offering identity monitoring.
- Maine State AGas victim2023-03-17
Cardiovascular Associates, a healthcare organization, reported an external system breach (hacking) that occurred between November 28, 2022, and December 5, 2022. The breach was discovered on February 16, 2023. The compromised information includes names and Social Security numbers. A total of 441,640 individuals were affected, including 2 Maine residents. Affected individuals were notified on March 17, 2023, and offered 12 months of credit monitoring and identity theft protection services through IDX.
- New Hampshire State AGas victim2023-02-06
Cardiovascular Associates, a physician practice in Alabama, notified the New Hampshire Attorney General of a data breach affecting 91 NH residents. Unauthorized access occurred between Nov 28 and Dec 5, 2022. Exfiltrated data included names, SSNs, medical records, and financial info. CVA engaged forensic investigators, enhanced security, and offered 12 months of credit monitoring.
- California State AGas victim2023-02-03
Cardiovascular Associates disclosed an unauthorized access incident affecting patient data in Alabama. An external actor accessed systems between Nov 28 and Dec 5, 2022, exfiltrating PHI, PII, and financial data. The breach was discovered on Dec 5, 2022. Forensic investigation was engaged, and identity monitoring was offered to affected individuals.
- Vermont State AGas victim2023-02-03
Cardiovascular Associates notified patients of a data breach where unauthorized access occurred between Nov 28 and Dec 5, 2022. Personal information including names, SSNs, medical records, and financial data was accessed. A forensic firm was engaged, and affected individuals were offered credit monitoring.
- Massachusetts State AGas victim2023-02-03
Cardiovascular Associates reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-02-03. 188 Massachusetts residents were affected. The report records the breach type as electronic.
- ALABAMAHHS OCRas victim2023-02-03
Cardiovascular Associates reported to HHS on 2023-02-03 a Hacking/IT Incident affecting 433,348 individuals. Breached information located on Network Server. PHI included names, addresses, DOB, SSNs, health insurance, medical/treatment info, billing/claims, passport/Driver's license numbers, and financial information.
- Montana State AGas victim2023-02-03
Cardiovascular Associates notified patients of a data breach where an unauthorized third party accessed systems and exfiltrated data between Nov 28 and Dec 5, 2022. Discovered Dec 5, 2022. Data included PHI, SSNs, and financial info. Forensic firm engaged; credit monitoring offered.
- South Carolina State AGas victim2023-02-03
Cardiovascular Associates notified patients of a data breach where unauthorized access occurred between Nov 28 and Dec 5, 2022. Personal info, PHI, SSNs, and financial data were accessed. A forensic firm was engaged. Identity monitoring offered via IDX.