Outcomes
ent_3b5cd80e365d9fbe2ddb3004
Disclosures
8
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
257,481
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Outcomes
- Normalized
- outcomes— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- outcomes.com
Disclosure history (8)newest first
- Texas State AGas victim2025-10-24
Outcomes One, Inc. based in Orlando, Florida, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-09-10 and reported on 2025-10-24. 18,299 Texas residents were affected. 256,031 individuals affected in total. Types of information involved: Name of individual;Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
- California State AGas victim2025-10-23
Outcomes One, Inc. experienced a phishing incident on July 1, 2025, resulting in unauthorized access to an employee's email account. The attacker accessed files and emails containing demographic and health insurance information for some individuals. Social Security numbers were not involved. Outcomes secured the account, engaged third-party investigators, and implemented enhanced security safeguards and employee training.
- Washington State AGas victim2025-09-23
Outcomes One, Inc. reported a phishing incident on July 1, 2025, affecting one employee's email account. Unauthorized access occurred for approximately one hour. Data accessed included names, medical provider names, health insurance info, and medication info for 3,477 Washington residents (Aetna Health Insurance Company members). Notification sent September 23, 2025.
- California State AGas victim2025-09-23
Outcomes One, Inc. notified California residents of a phishing incident on July 1, 2025, where an employee's email account was compromised. Unauthorized access lasted approximately one hour. Affected data may include names, demographic information, medical provider names, health insurance information, and medication information. Social Security numbers were not involved. The company engaged an outside specialist, secured the account, and implemented enhanced email safeguards and phishing training.
- Oregon State AGas victim2025-09-23
Outcomes One, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-09-23. The breach occurred during 7/1/2025 - 7/1/2025. The breach was discovered on 7/25/2025. 149,094 individuals were affected. Notice was sent on 9/23/2025.
- FLORIDAHHS OCRas victim2025-09-23
Outcomes One, Inc., a Florida-based business associate, reported to HHS on 2025-09-23 a Hacking/IT Incident (email phishing) affecting 257,481 individuals. An employee was targeted in an email phishing scheme, exposing PHI including names, dates of birth, medications, and other treatment information. Breached information was located in Email. The BA notified HHS, affected covered entities, individuals, the media, and provided substitute notice. Additional administrative, technical, and security safeguards were implemented and workforce members were retrained.
- Montana State AGas victim2025-09-23
Outcomes One, Inc. notified Montana residents of a phishing incident on July 1, 2025, affecting a single employee's email account. Unauthorized access lasted approximately one hour, exposing names, demographic info, medical provider names, health insurance info, and medication information. No SSNs were involved. Outcomes engaged outside specialists and enhanced security training.
- Illinois State AGas victim2025-09-01
OUTCOMES ONE, INC. filed a data-breach notice with the Illinois Attorney General in September 2025 (case 25-09-480). The register records the breach as discovered on September 10, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.