DMS Health
ent_3fd8970f80e5e34c05e0a85d
Disclosures
9
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
48,336
nationwide · HHS OCR ND
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DMS Health
- Normalized
- dms health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- dmshealth.com
Disclosure history (9)newest first
- Delaware State AGas victim2023-11-10
DMS Health Technologies, a business partner providing imaging services to covered entities, notified individuals of unauthorized network access occurring between March 27 and April 24, 2023. Suspicious activity was detected on April 23, 2023. While no definitive proof of data acquisition was found, potentially affected data included names, Social Security numbers, dates of birth, and addresses. DMS engaged forensic specialists, secured the network, and notified federal law enforcement and HHS. The notice covers residents of multiple states, including Delaware, DC, Maryland, New Mexico, New York, North Carolina, and Rhode Island.
- Delaware State AGas reporting2023-11-10
DMS Health Technologies, a business partner of Nanticoke Memorial Hospital, issued a notice of security incident on November 8, 2023. The incident potentially involved patient information. DMS stated there is no indication the information was misused.
- Montana State AGas victim2023-10-04
DMS Health Technologies notified Montana residents of unauthorized network access between March 27 and April 24, 2023. Suspicious activity was detected on April 23, 2023. The incident potentially involved PII and PHI. DMS engaged forensic specialists, notified HHS and law enforcement, and provided 12 months of identity monitoring.
- Massachusetts State AGas victim2023-10-04
DMS Health Technologies reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-04. 42 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-10-04
DMS Health Technologies reported a data breach impacting 3,093 individuals. The incident, which occurred between March 27, 2023, and April 24, 2023, was discovered on April 23, 2023. The breach was described as an external system breach (hacking), resulting in the compromise of names and Social Security numbers. Affected individuals were notified on September 21, 2023, and offered 12 months of credit monitoring and identity restoration services through Kroll.
- Indiana State AGas reporting2023-09-21
DMS Healt Technologies reported a data breach to the Indiana Attorney General. The breach occurred on 2023-03-07 and was reported on 2023-09-21. 27 Indiana residents were affected. 3,093 individuals affected in total.
- NORTH DAKOTAHHS OCRas victim2023-06-21
DMS Health Technologies, Inc. (ND) reported to HHS on 2023-06-21 a Hacking/IT Incident affecting approximately 48,336 individuals. Breached information was located on a Network Server. PHI compromised included names, addresses, dates of birth, Social Security numbers, lab results, and other treatment information. The CE notified HHS, affected individuals, and the media, posted substitute notice, and implemented additional administrative, technical, and security safeguards. OCR provided technical assistance.
- Illinois State AGas victim2023-01-01
DMS HEALTH TECHNOLOGIES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-705). The register records the breach as discovered on April 23, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
DMS HEALTH TECHNOLOGIES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-696). The register records the breach as discovered on March 27, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.