21st Century Oncology
ent_ad4060a4849f75f5898124e4
Disclosures
8
HHS OCR enforcement · State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,213,597
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 21st Century Oncology
- Normalized
- 21st century oncology— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- 21co.com
Disclosure history (8)newest first
- FEDERALHHS OCR enforcementas victim2017-12-28
21st Century Oncology, Inc. agreed to pay $2.3 million to settle potential HIPAA Privacy and Security Rules violations. The entity, a cancer care provider, adopted a corrective action plan. The settlement occurred in the context of the company's Chapter 11 bankruptcy proceedings.
- South Carolina State AGas victim2016-04-28
21st Century Oncology notified patients that an unauthorized third party accessed a database containing names, SSNs, diagnosis/treatment info, and insurance data. The intrusion occurred on Oct 3, 2015, and was discovered on Nov 13, 2015, after FBI notification. Notification was delayed per FBI request. The company hired forensic investigators and enhanced security protocols. No evidence of medical record access or misuse was found. Affected individuals were offered one year of credit monitoring.
- Massachusetts State AGas victim2016-04-27
21st Century Oncology Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-04-27. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2016-03-14
21st Century Oncology notified patients of a data breach where an unauthorized third party accessed a database containing names, SSNs, and medical/insurance info. The FBI advised the company on Nov 13, 2015, though access likely occurred on Oct 3, 2015. Notifications were sent in April 2016 following an FBI delay request. Forensic investigators were engaged, and credit monitoring was offered.
- Washington State AGas victim2016-03-04
21st Century Oncology notified the Washington AG that the FBI advised on Nov 13, 2015, that an unauthorized third party illegally obtained patient information from a database. Access likely occurred on Oct 3, 2015. Data included names, SSNs, diagnosis, treatment, and insurance info. 2,802 WA residents were notified. The FBI requested a notification delay. The incident is under active FBI investigation.
- California State AGas victim2016-03-04
21st Century Oncology notified patients that an unauthorized third party may have accessed a database containing patient information, including names, Social Security numbers, physician names, diagnosis/treatment info, and insurance data. The intrusion occurred on October 3, 2015, but the company was notified by the FBI on November 13, 2015. Notification was delayed per FBI request. The company engaged forensic investigators, enhanced security protocols, and offered one year of identity protection services.
- New Hampshire State AGas victim2016-03-04
21st Century Oncology notified the NH Attorney General of a breach where an unauthorized third party accessed a database containing patient names, SSNs, and PHI. The incident occurred around Oct 3, 2015, and was discovered on Nov 13, 2015, via FBI notification. 1,202 NH residents were notified. The company engaged forensic investigators and enhanced security protocols.
- FLORIDAHHS OCRas victim2016-03-04
21st Century Oncology, Inc. reported to HHS on 2016-03-04 a Hacking/IT Incident affecting 2,213,597 individuals. Breached information located on Network Server. The attacker accessed the SQL database via remote desktop protocol starting October 3, 2015. Patient names, SSNs, diagnoses, and insurance info were exposed. 21CO settled for $2.3 million and implemented a corrective action plan.