HealthFitness
ent_4b4cfe8d57a81349f7de9652
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
20,790
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HealthFitness
- Normalized
- healthfitness— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- ILLINOISHHS OCRas victim2019-01-25
HealthFitness reported to HHS on 2019-01-25 a Unauthorized Access/Disclosure affecting 1808 individuals. Breached information located on Other. The incident involved a software misconfiguration on a server housing ePHI, discovered on June 27, 2018. Health Fitness, a business associate, failed to conduct a thorough risk analysis. A $227,816 settlement was reached with OCR.
- ILLINOISHHS OCRas victim2018-10-15
HealthFitness (Health Fitness Corporation), a business associate in IL, reported to HHS OCR on 2018-10-15 an Unauthorized Access/Disclosure affecting 20,790 individuals. Beginning approximately August 2015, ePHI became discoverable on the internet due to a software misconfiguration on the server, exposing it to web crawlers. The breach was discovered on June 27, 2018. OCR settled for $227,816 under its Risk Analysis Initiative.
- Montana State AGas reporting2018-10-05
North American Risk Services, Inc. reported unauthorized access to employee email accounts from Feb 7 to Mar 27, 2018. The breach exposed names and SSNs of 2 Montana residents. NARS confirmed the breach on June 27, 2018, engaged forensic investigators, and began notifying affected individuals on Aug 31, 2018, offering credit monitoring.