CodeMetro
ent_b37aa2ef5853397862c85aa4
Disclosures
9
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
62,807
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CodeMetro
- Normalized
- codemetro— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- codemetro.com
Disclosure history (9)newest first
- Indiana State AGas victim2020-06-19
CodeMetro reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-20 and was reported on 2020-06-19. 15 Indiana residents were affected. 10,548 individuals affected in total.
- California State AGas victim2020-06-19
CodeMetro suffered a ransomware attack on April 21, 2020, which was detected within hours. Attackers accessed a database server, copied and removed data, and deployed ransomware. Affected data included health-related patient information (PHI), personal identifiers (SSN, DOB), school information, and employee payroll data. CodeMetro engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring via TransUnion.
- Massachusetts State AGas victim2020-06-19
CodeMetro reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-06-19. 816 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2020-06-19
CodeMetro, a software provider for applied behavior analysis, suffered a ransomware attack on April 21, 2020. Attackers accessed a database server containing employee payroll information, including names, addresses, SSNs, driver's license numbers, and dates of birth, before deploying ransomware. Data was copied and removed. 41 New Hampshire residents were affected. CodeMetro contained the threat, engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring.
- CALIFORNIAHHS OCRas victim2020-06-19
CodeMetro, Inc. reported to HHS on 2020-06-19 a Hacking/IT Incident affecting 62,807 individuals. Breached information located on Network Server. The cyber-attack affected electronic protected health information (ePHI) including names, SSNs, addresses, DOB, diagnoses, and insurance data. CodeMetro acted as a Business Associate. Response included notifying HHS, individuals, and media, workforce retraining, and implementation of technical safeguards.
- Montana State AGas victim2020-06-19
CodeMetro suffered a ransomware attack on April 21, 2020, which resulted in the exfiltration of patient and employee data including SSNs, health information, and financial details. The incident was detected within hours, law enforcement was notified, and forensic investigators were engaged. Affected individuals were offered one year of credit monitoring.
- California State AGas victim2020-06-16
CodeMetro, a provider of software solutions to applied behavior analysis providers, suffered a ransomware attack on April 21, 2020. The attackers accessed a database server, copied and removed health-related patient information including names, contact details, school information, insurance data, and medical records. CodeMetro contained the threat, engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring to affected individuals.
- Illinois State AGas victim2020-01-01
CODEMETRO filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-240). The register records the breach as discovered on June 19, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
CODEMETRO filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-250). The register records the breach as discovered on June 19, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.