Newkirk Products, Inc.
ent_aea9eb2d15a8965aedadd961
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,466,120
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Newkirk Products, Inc.
- Normalized
- newkirk products— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Montana State AGas victim2016-08-19
Newkirk Products, Inc., a healthcare ID card service provider, disclosed that a server containing member information for Symphonix Health was accessed without authorization starting May 21, 2016. The breach was discovered on July 6, 2016. Data potentially accessed included names, addresses, DOBs, and plan details, but no SSNs or medical records. Newkirk engaged forensic investigators, notified law enforcement, and offered two years of identity protection services.
- California State AGas victim2016-08-18
Newkirk Products, Inc. filed a data breach notification with the California Attorney General. The breach occurred on May 21, 2016. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- Oregon State AGas victim2016-08-17
Newkirk Products, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2016-08-17. The breach occurred during 5/21/2016. The breach was discovered on 7/6/2016. 3,466,120 individuals were affected. Notice was sent on 8/8/2016.
- NEW YORKHHS OCRas victim2016-08-09
Newkirk Products, Inc. (NY), a business associate issuing member healthcare ID cards, reported to HHS OCR on 2016-08-09 a Hacking/IT Incident affecting 3,466,120 individuals. Prior to its acquisition by a new parent company, unauthorized individuals accessed a network server containing ePHI of ~3.99M health plan members. Exposed data included names, addresses, plan/group/member IDs, dependent names, primary care provider, and in some cases Medicaid IDs, dates of birth, and premium invoice information. The former parent decommissioned the server; a new IT environment was established. OCR required a risk analysis, remediation plan, and updated HIPAA policies.