Comprehensive Health Services
ent_74fbe557f84fe5e1ab7f926c
Disclosures
15
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
106,752
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Comprehensive Health Services
- Normalized
- comprehensive health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (15)newest first
- Maine State AGas victim2022-03-16
Comprehensive Health Services reported a data breach affecting 602 Maine residents. The breach, which occurred between April 9, 2020, and October 22, 2020, was discovered on September 30, 2020. The incident involved an external system breach (hacking), resulting in the acquisition of names and Social Security numbers. The company began notifying affected individuals on February 15, 2022, and offered 12 to 24 months of credit monitoring and identity theft protection services through Equifax.
- California State AGas victim2022-03-16
Comprehensive Health Services (CHS) experienced a cyber intrusion between April 9, 2020, and October 22, 2020. CHS detected suspicious activity and launched an investigation, engaging cybersecurity experts and notifying the FBI. On November 3, 2021, CHS confirmed that personal information of current and former employees, contained in invoicing files pre-dating 2019, may have been accessed or acquired without authorization. CHS implemented enhanced network security measures, including endpoint detection and response tools, and offered complimentary identity protection services to affected individuals.
- Oregon State AGas victim2022-03-16
Comprehensive Health Services reported a data breach to the Oregon Attorney General. The breach was reported on 2022-03-16. The breach occurred during 4/9/2020 - 10/22/2020. The breach was discovered on 9/30/2020. 95,297 individuals were affected. Notice was sent on 2/15/20223/14/2022.
- New Hampshire State AGas victim2022-03-15
Comprehensive Health Services (CHS), a subsidiary of Acuity International, notified the NH Attorney General of a supplemental data breach affecting 428 NH residents. CHS detected unusual activity and fraudulent wire transfers on September 30, 2020. The investigation revealed unauthorized access to invoicing files containing names and Social Security numbers of current and former employees of a customer. CHS engaged forensic experts, notified the FBI, and implemented enhanced security measures including EDR tools and penetration testing. Credit monitoring was offered to affected individuals.
- New Hampshire State AGas victim2022-02-15
Comprehensive Health Services (CHS) notified the New Hampshire Attorney General on February 15, 2022, regarding a data security incident affecting 427 NH residents. CHS detected unusual activity on September 30, 2020, following fraudulent wire transfers. Investigation concluded November 3, 2021, revealing unauthorized access to invoicing files containing names and SSNs of a customer's employees. CHS engaged forensic experts, notified the FBI, and offered credit monitoring.
- Washington State AGas victim2022-02-15
Acuity International subsidiary Comprehensive Health Services (CHS) reported a cybersecurity incident affecting 2,785 Washington residents. Unauthorized access occurred between April 9, 2020, and October 22, 2020, following suspicious activity detected on September 30, 2020. The breach involved names and Social Security numbers of current and former employees of CHS customers. CHS engaged forensic experts, notified the FBI, and provided credit monitoring services.
- FLORIDAHHS OCRas victim2022-02-15
Comprehensive Health Services (FL) reported to HHS on 2022-02-15 a Hacking/IT Incident (email phishing scheme) affecting 106,752 individuals. Several employees were victims of a phishing attack that compromised PHI including names, Social Security numbers, and drug testing invoices. Breached information located on Email. The CE notified HHS, individuals, and media; offered credit monitoring; and implemented additional administrative and technical safeguards.
- Maine State AGas victim2022-02-15
Comprehensive Health Services, a healthcare organization, reported an external system breach affecting 94,449 individuals. The incident occurred between April 9, 2020, and October 22, 2020, and was discovered on September 30, 2020. The compromised data included names and Social Security numbers. The company began notifying affected individuals in writing on February 15, 2022, and offered 12 to 24 months of identity theft protection services through Equifax.
- Montana State AGas victim2022-02-15
Comprehensive Health Services (CHS) notified Montana residents of a cyber intrusion detected on November 3, 2021. The incident involved unauthorized access to pre-2019 invoicing files containing personal information of current and former employees of CHS clients. CHS engaged forensic experts, reported the incident to the FBI, and implemented enhanced network security measures including new EDR tools. No evidence of misuse was found.
- California State AGas victim2022-02-15
Comprehensive Health Services (CHS) experienced a cyber intrusion affecting personal information of current and former employees of its clients. The breach window is April 9, 2020, to October 22, 2020. CHS detected suspicious activity and engaged cybersecurity experts and the FBI. Affected data may include names, addresses, and financial information found in invoicing files. CHS implemented enhanced network security measures, including new endpoint detection tools and penetration testing, and offered complimentary credit monitoring through Equifax.
- Oregon State AGas victim2022-02-15
Comprehensive Health Services reported a data breach to the Oregon Attorney General. The breach was reported on 2022-02-15. The breach occurred during 4/9/2020 - 10/22/2020. The breach was discovered on 9/30/2020. 94,449 individuals were affected. Notice was sent on 2/15/2022.
- Massachusetts State AGas victim2022-01-20
Comprehensive Health Services reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-01-20. 1,533 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2022-01-20
Comprehensive Health Services (CHS) notified the New Hampshire Attorney General of a data security incident affecting one NH resident. CHS detected unusual activity on September 30, 2020, following fraudulent wire transfers, indicating credential compromise. The investigation concluded on November 3, 2021, that personal information (names, SSNs) of a limited number of individuals employed by customer Anchor QEA, LLC was accessed. Notification was sent on January 20, 2022, offering credit monitoring.
- Illinois State AGas victim2022-01-01
COMPREHENSIVE HEALTH SERVICES filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-117). The register records the breach as discovered on September 30, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
COMPREHENSIVE HEALTH SERVICES filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-190). The register records the breach as discovered on September 30, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.