BioReference Laboratories Inc.
ent_2b0396b62c51280f23c972f8
Disclosures
3
HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
425,749
as filed · HHS OCR NJ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BioReference Laboratories Inc.
- Normalized
- bioreference laboratories— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- NJHHS OCRas victim2019-07-30
BioReference Laboratories, Inc. (NJ) reported to HHS OCR on 2019-07-30 a Hacking/IT Incident affecting 425,749 individuals. The breach occurred at business associate Retrieval-Masters Creditors Bureau, Inc. d/b/a American Medical Collection Agency (AMCA), which was the victim of a cyber-attack. ePHI exposed included names, birthdates, clinical information, health insurance information, and treatment information. The CE notified HHS, affected individuals, and media; implemented additional administrative safeguards; and terminated its relationship with AMCA. OCR investigation completed.
- NJHHS OCRas victim2016-04-08
BioReference Laboratories, Inc. (NJ) reported to HHS OCR on 2016-04-08 an Unauthorized Access/Disclosure affecting 3,563 individuals. Several employees took pictures of documents containing PHI, including names, dates of birth, addresses, health insurance information, SSNs, diagnoses, and lab results. OCR investigated and the CE implemented new handheld-device policies, encrypted communications tools, and offered credit monitoring to affected individuals. Breached information located on: Other.
- NJHHS OCRas victim2014-07-23
BioReference Laboratories, Inc. (NJ) reported to HHS OCR on 2014-07-23 an Unauthorized Access/Disclosure affecting 3,334 individuals. The covered entity's business associate inadvertently made ePHI viewable over the Internet via a network server. Exposed data included names, addresses, dates of birth, Social Security numbers, and treatment information. Following OCR investigation, the CE and BA implemented additional administrative and technical safeguards, and OCR obtained assurances of corrective action.