Cogent Healthcare, Inc.
ent_056284a4cad9d678a1540d2c
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
32,000
nationwide · HHS OCR TN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cogent Healthcare, Inc.
- Normalized
- cogent healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- TENNESSEEHHS OCRas victim2013-08-30
Cogent Healthcare, Inc. (TN), a business associate providing management services for 24 hospitalist service providers, reported a breach to HHS on 2013-08-30 affecting approximately 32,000 individuals. The BA's privacy officer discovered that PHI was publicly accessible on an FTP Internet site. Exposed data included patient names, physicians' names, dates of birth, diagnoses, treatment summaries, medical histories, and medical record numbers. OCR determined the incident predated the Sept. 23, 2013 BA enforcement date and provided technical assistance.
- California State AGas victim2013-08-08
Cogent Healthcare, Inc. disclosed a security lapse involving its third-party vendor, M2ComSys, a medical transcription company. Between May 5, 2013, and June 24, 2013, protected health information (PHI) including patient names, dates of birth, diagnoses, and treatment summaries was accessible via an insecure internet site. Cogent discovered the lapse on June 24, 2013, and immediately contained the access. The company ended its relationship with M2, secured the hardware, and confirmed removal of indexed data from Google. No Social Security numbers were involved.
- TENNESSEEHHS OCRas victim2009-11-25
Cogent Healthcare, Inc. (TN, Business Associate) reported to HHS OCR on 2009-11-25 a laptop theft affecting 6,400 individuals. A laptop was stolen from a locked office at Aurora St. Lukes Medical Center. Breached information — stored on the laptop — included patient names, dates of birth, Social Security numbers, medical record numbers, and in some cases diagnosis codes. Corrective actions included accelerated laptop encryption, improved physical security, staff training, and encryption of portable media.