Data Media Associates
ent_0cfcb61d840fe61dcc744404
Disclosures
17
HHS OCR · State AG · 11 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
100,644
nationwide · HHS OCR GA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Data Media Associates
- Normalized
- data media associates— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (17)newest first
- GEORGIAHHS OCRas victim2023-10-09
HHS OCR breach portal entry: Data Media Associates (GA, Business Associate), 2,035 individuals affected, reported 2023-10-09. Type: Unauthorized Access/Disclosure; Location: Paper/Films. Web description attributes the underlying incident to business associate NASCO, which reported a software application exposed PHI of 1,744,655 individuals (names, DOB, addresses, SSNs, diagnoses, claims and health insurance/treatment information). Note: the 1,744,655 figure refers to NASCO's overall reported breach population, while this specific OCR row lists 2,035 individuals tied to Data Media Associates.
- Washington State AGas victim2023-09-25
Data Media Associates, LLC notified Washington AG of unauthorized access to MOVEit Transfer data on June 4, 2023. Investigation confirmed data acquisition by June 30, 2023. 657 WA residents affected. Data included names, addresses, health insurance info, and potentially SSNs. DMA patched system, engaged experts, and offered credit monitoring.
- Massachusetts State AGas victim2023-09-25
Data Media Associates, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-25. 2,793 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-09-25
Data Media Associates, LLC was impacted by the MOVEit vulnerability exploit between May 31 and June 1, 2023. The breach was discovered on June 30, 2023, and exposed the names and Social Security numbers of 133 Maine residents. The company offered affected individuals 12 months of identity theft protection services.
- Delaware State AGas victim2023-08-30
Data Media Associates, LLC notified Delaware AG on August 23, 2023, of a data security incident involving the MOVEit Transfer software vulnerability. The incident, discovered in June 2023, potentially exposed protected health information (PHI) and personal data of individuals associated with DMA's healthcare clients. DMA patched the system, engaged external experts, and is notifying affected individuals.
- New Hampshire State AGas victim2023-08-28
Data Media Associates, LLC (DMA), a healthcare billing fulfillment provider, notified the NH AG of a data security incident involving the MOVEit Transfer vulnerability. DMA became aware of the CISA alert on June 4, 2023, and confirmed unauthorized data acquisition on June 30, 2023. 182 NH residents were notified on August 23, 2023. Affected data included PHI and personal identifiers. DMA patched the system, engaged experts, and offered credit monitoring.
- GEORGIAHHS OCRas victim2023-08-24
Data Media Associates reported to HHS on 2023-08-24 a Hacking/IT Incident affecting 100,644 individuals. Breached information located on Network Server. A software application exposed PHI including names, addresses, SSNs, and health insurance info. The BA notified HHS, individuals, and media, and strengthened technical safeguards.
- Indiana State AGas victim2023-08-23
Data Media Associates, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-31 and was reported on 2023-08-23. 1,722 Indiana residents were affected. 98,496 individuals affected in total.
- California State AGas victim2023-08-23
Data Media Associates, LLC disclosed a data breach affecting protected health information due to the exploitation of a critical vulnerability in MOVEit Transfer software. The incident occurred between May 31 and June 1, 2023, and was discovered in June 2023. Affected data may include names, addresses, health insurance IDs (potentially SSNs), and other PHI. The company patched the system, engaged external experts, and offered identity theft protection services.
- Montana State AGas victim2023-08-23
Data Media Associates, LLC notified Montana residents in August 2023 of a June 2023 data security incident involving the MOVEit Transfer vulnerability. Unauthorized access may have exposed protected health information, including health insurance ID numbers potentially linked to SSNs. DMA patched the system, engaged external experts, and offered identity theft protection services.
- Oregon State AGas victim2023-08-23
Data Media Associates, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-23. 74,730 individuals were affected.
- Delaware State AGas victim2023-08-23
Data Media Associates, LLC (DMA) notified Delaware residents of a data security incident involving its MOVEit Transfer software. In June 2023, DMA discovered a critical vulnerability in the managed file transfer solution and patched the system. An investigation revealed that unauthorized actors acquired certain data, potentially including protected health information (PHI), names, and government IDs. DMA engaged external experts, patched the system, and is evaluating additional safeguards. The incident affected approximately 2,500 organizations worldwide.
- Massachusetts State AGas victim2023-08-23
Data Media Associates, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-23. 2,788 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-08-23
Data Media Associates, LLC reported a data breach affecting 131 Maine residents. The incident occurred between May 31, 2023, and June 1, 2023, and was discovered on June 30, 2023. The compromised information included names and Social Security numbers. The company offered 12 months of identity theft protection services through IDX.
- Illinois State AGas victim2023-01-01
DATA MEDIA ASSOC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-663). The register records the breach as discovered on June 4, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
DATA MEDIA ASSOC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-618). The register records the breach as discovered on June 4, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GEORGIAHHS OCRas victim2014-02-28
Data Media (GA), a Business Associate, reported to HHS OCR on 2014-02-28 a breach of type 'Other' affecting 600 individuals. The breached information was located on an 'Other' medium. No further details are available from the HHS web description.