RECOVERY HEALTH SERVICES, INC.
ent_019e6281aeb2fd92105018907ffa7023
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
20,485
nationwide · HHS OCR OH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- RECOVERY HEALTH SERVICES, INC.
- Normalized
- recovery health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300PRXFTRDXC68G83
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Montana State AGas victim2019-05-05
Health Recovery Services, Inc. notified Montana regulators of unauthorized network access occurring from Nov 14, 2018 to Feb 5, 2019. Discovered Feb 5, 2019. Potential exposure of PHI, SSNs, and demographics. Forensic experts could not rule out access to patient data. HRS engaged Kroll for credit monitoring and rebuilt its network.
- Massachusetts State AGas victim2019-04-05
Health Recovery Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-04-05. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- OHIOHHS OCRas victim2019-04-05
Health Recovery Services, Inc. reported to HHS on 2019-04-05 a Hacking/IT Incident affecting 20485 individuals. Breached information located on Network Server. The cyber-attack affected electronic protected health information (ePHI) including names, addresses, birthdates, telephone numbers, Social Security numbers, diagnoses, treatment information, and health insurance information. The CE implemented new technical safeguards.
- Illinois State AGas victim2019-01-01
HEALTH RECOVERY SERVICES, INC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-178). The register records the breach as discovered on November 14, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.