Onsite Mammography
ent_aff20a0b741835ea
Disclosures
5
State AG · HHS OCR · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
357,265
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Onsite Mammography
- Normalized
- onsite mammography— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🍁Vermont State AGas victim2025-04-21
Onsite Mammography, LLC notified consumers of a data security incident discovered in October 2024 involving unauthorized access to an employee's email account. The incident exposed patients' names and specific health-related information (PHI). The company engaged independent cybersecurity experts and a data analytics vendor to investigate and assess the scope.
- MASSACHUSETTSHHS OCRas victim2025-04-21
Onsite Mammography reported to HHS on 2025-04-21 a Hacking/IT Incident affecting 357265 individuals. Breached information located on Email. Business Associate present: Yes.
- 🏎️Indiana State AGas victim2025-04-21
Onsite Mammography reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-02 and was reported on 2025-04-21. 6,529 Indiana residents were affected. 357,265 individuals affected in total.
- ⛰️New Hampshire State AGas victim2025-04-21
Onsite Mammography, LLC notified the New Hampshire Attorney General of a data security incident affecting approximately 39 New Hampshire residents. The incident involved unauthorized access to an employee's email account in October 2024, likely via phishing. The actor accessed email content potentially containing PII and PHI. Onsite engaged cybersecurity experts, reset passwords, notified law enforcement, and is offering credit monitoring services.
- 🦞Maine State AGas victim2025-04-21
In October 2024, an unauthorized actor gained access to a single employee email account at Onsite Mammography LLC, a national healthcare imaging services provider. The intrusion was discovered on April 15, 2025 following a data analytics vendor review concluding February 21, 2025. PHI and PII of patients may have been exposed. The actor did not access other systems. 357,265 individuals were affected nationally; 32 Maine residents. Equifax credit monitoring (12 months) was offered.