Concentra
ent_b33184acfdc9cc43e91c91fe
Disclosures
3
HHS OCR enforcement · State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
22,088
nationwide · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Concentra
- Normalized
- concentra— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- concentra.hpcontent.com
Disclosure history (3)newest first
- FEDERALHHS OCR enforcementas victim2025-04-30
HHS OCR settled allegations against Concentra Inc. for failing to comply with the HIPAA Privacy Rule's right of access standard (45 C.F.R. § 164.524(b)) by not responding appropriately to patient requests for medical records. Concentra agreed to pay $112,500 to resolve the matter.
- Washington State AGas victim2023-11-03
PJ&A filed a supplemental Washington AG notice for a breach affecting Concentra, Inc. patients. Unauthorized access occurred March 27-May 2, 2023 via compromised RDS credentials. Data included PHI, SSNs, and financial info. 22,088 individuals affected; 21,075 in WA. Notices mailed Nov 3, 2023.
- TEXASHHS OCRas victim2010-01-19
Concentra reported to HHS on 2010-01-19 a Theft affecting 900 individuals. Breached information located on Laptop. An unencrypted laptop containing ePHI (demographic and clinical data) of approximately 900 patients was stolen from a facility. The CE filed a police report, notified patients, HHS, and media, and implemented corrective actions including device identification, safeguard implementation, and equipment replacement.