Cogent Healthcare, Inc.
ent_056284a4cad9d678a1540d2c
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
32,000
as filed · HHS OCR TN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cogent Healthcare, Inc.
- Normalized
- cogent healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- TNHHS OCRas victim2013-08-30
Cogent Healthcare, Inc. (TN), a business associate providing management services for 24 hospitalist service providers, reported a breach to HHS on 2013-08-30 affecting approximately 32,000 individuals. The BA's privacy officer discovered that PHI was publicly accessible on an FTP Internet site. Exposed data included patient names, physicians' names, dates of birth, diagnoses, treatment summaries, medical histories, and medical record numbers. OCR determined the incident predated the Sept. 23, 2013 BA enforcement date and provided technical assistance.
- 🐻California State AGas victim2013-08-08
Cogent Healthcare, Inc. disclosed a security lapse involving third-party vendor M2ComSys, a medical transcription company. Between May 5, 2013, and June 24, 2013, unauthorized parties accessed patient care notes containing PHI, including patient names, DOBs, diagnoses, and medical record numbers. No Social Security numbers or copies of medical records were included. Cogent ended its relationship with M2, recovered hardware, and worked with Google to remove indexed PHI. Affected individuals were offered one year of Experian’s ProtectMyID credit monitoring and fraud resolution services.
- TNHHS OCRas victim2009-11-25
Cogent Healthcare, Inc. (TN, Business Associate) reported to HHS OCR on 2009-11-25 a laptop theft affecting 6,400 individuals. A laptop was stolen from a locked office at Aurora St. Lukes Medical Center. Breached information — stored on the laptop — included patient names, dates of birth, Social Security numbers, medical record numbers, and in some cases diagnosis codes. Corrective actions included accelerated laptop encryption, improved physical security, staff training, and encryption of portable media.