Assured Imaging
ent_3bcedca7b93a106d0c639843
Disclosures
7
HHS OCR enforcement · Leak Site · State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
244,813
nationwide · HHS OCR AZ
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Assured Imaging
- Normalized
- assured imaging— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- FEDERALHHS OCR enforcementas victim2025-12-05
HHS OCR settled with Assured Imaging regarding a May 2020 ransomware incident involving PYSA malware that encrypted medical records and exfiltrated PHI of ~244,813 individuals. Assured failed to conduct a required Security Rule risk analysis and delayed individual notification. The settlement requires a $375,000 payment and a two-year Corrective Action Plan including risk analysis, risk management, policy updates, and workforce training.
- GLOBALLeak Siteas victim2021-09-09
- Washington State AGas victim2020-08-31
Assured Imaging disclosed a ransomware attack on its electronic medical records system. Unauthorized access occurred May 15-17, 2020, discovered May 19, 2020. Limited patient and employee data (PII, PHI, financial) was exfiltrated. 37,702 Washington residents notified. Forensic investigators engaged; credit monitoring offered.
- California State AGas victim2020-08-31
Assured Imaging experienced a ransomware attack on May 19, 2020, encrypting its electronic medical records system. An investigation confirmed unauthorized access and data exfiltration between May 15 and May 17, 2020. Affected data included PHI, PII (SSN, DL), and financial account numbers for patients and employees. The company restored systems, engaged forensics, notified HHS, and offered credit monitoring.
- Montana State AGas victim2020-08-31
Assured Imaging disclosed a ransomware incident in May 2020 that encrypted electronic medical records. Unauthorized access occurred May 15-17, 2020, resulting in data exfiltration. Affected data included PHI, SSNs, driver's licenses, and bank account numbers. Assured engaged forensic specialists, restored systems, and offered 12 months of credit monitoring. No specific victim count was provided in this Montana filing.
- Oregon State AGas victim2020-08-31
Assured Imaging reported a data breach to the Oregon Attorney General. The breach was reported on 2020-08-31. The breach occurred during 5/19/2020. The breach was discovered on 7/1/2020. 165,274 individuals were affected. Notice was sent on 8/31/2020.
- ARIZONAHHS OCRas victim2020-08-27
Assured Imaging (AZ) reported to HHS OCR on 2020-08-27 a Hacking/IT Incident affecting 244,813 individuals. Breached information was located on a Network Server. No business associate was identified as present. No further detail is available from the HHS web description.