U.S. HealthWorks
ent_8d7337347f2f25f85100e5df
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
10,673
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- U.S. HealthWorks
- Normalized
- us healthworks— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Concentra Group Holdings Parent, Inc.— per SEC Exhibit 21 filing
Disclosure history (3)newest first
- AZHHS OCRas victim2025-02-06
U.S. HEALTHWORKS-SMMPP, L.C. reported to HHS on 2025-02-06 a Hacking/IT Incident affecting 10673 individuals. Breached information located on Network Server. Business Associate present.
- CALIFORNIAHHS OCRas victim2016-09-09
U.S. HealthWorks (CA) reported to HHS on 2016-09-09 a Theft affecting 1,400 individuals. On July 18, 2016, a CE-issued laptop and a notebook containing the laptop encryption password were stolen from an employee's automobile. Breached PHI included patient names, clinical information, visit dates, and SSNs for some patients. The CE notified HHS, affected individuals, and the media, offered credit monitoring for those with SSNs exposed, sanctioned the employee, and retrained staff. OCR provided Security Rule technical assistance. Breached information located on: Laptop.
- 🐻California State AGas victim2015-05-29
U.S. HealthWorks reported the theft of an employee's laptop on April 21, 2015, discovered on April 22, 2015. The laptop was password-protected but not encrypted. It may have contained employee names, addresses, dates of birth, job titles, and Social Security numbers. The company offered one year of Experian ProtectMyID Alert and is enhancing laptop encryption policies.