CONCENTRA HEALTH SERVICES, INC.
ent_019fb5ff4d1aacb70fac1c8c35e498e6
Disclosures
5
State AG · HHS OCR · HHS OCR enforcement · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,998,163
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CONCENTRA HEALTH SERVICES, INC.
- Normalized
- concentra health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500GB84105F75DE32
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Concentra Group Holdings Parent, Inc.— per SEC Exhibit 21 filing
Disclosure history (5)newest first
- California State AGas victim2024-02-08
Perry Johnson & Associates (PJ&A), a medical transcription vendor for Concentra Health Services, experienced unauthorized access to systems containing Concentra patient data between March 27 and May 2, 2023. PJ&A detected suspicious activity on May 2, 2023. The incident involved a third-party vendor compromise. Affected data includes names, addresses, and health information. PJ&A offered credit monitoring to affected individuals.
- TEXASHHS OCRas victim2024-01-09
Concentra Health Services, Inc. reported to HHS on 2024-01-09 a Hacking/IT Incident affecting 3,998,163 individuals. Breached information located on Network Server. A business associate experienced the hacking incident, exposing PHI including names, addresses, SSNs, and medical/claims data. The covered entity and business associate implemented security measures and provided credit monitoring.
- FEDERALHHS OCR enforcementas victim2014-04-22
Concentra Health Services settled potential HIPAA Privacy and Security Rules violations related to stolen laptops for $1,725,220 and adopted a corrective action plan.
- TEXASHHS OCRas victim2011-12-28
Concentra Health reported to HHS on 2011-12-28 a Theft affecting 870 individuals. Breached information located on Laptop.
- Massachusetts State AGas reporting2011-06-20
Concentra Medical Center reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2011-06-20. 23 Massachusetts residents were affected. The report records the breach type as electronic.