CodeMetro
ent_b37aa2ef5853397862c85aa4
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
62,807
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CodeMetro
- Normalized
- codemetro— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- codemetro.com
Disclosure history (4)newest first
- 🐻California State AGas victim2020-06-19
CodeMetro suffered a ransomware attack on April 21, 2020, which was detected within hours. Attackers accessed a database server, copied and removed data, and deployed ransomware. Affected data included health-related patient information (PHI), personal identifiers (SSN, DOB), school information, and employee payroll data. CodeMetro engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring via TransUnion.
- CALIFORNIAHHS OCRas victim2020-06-19
CodeMetro, Inc. reported to HHS on 2020-06-19 a Hacking/IT Incident affecting 62,807 individuals. Breached information located on Network Server. The cyber-attack affected electronic protected health information (ePHI) including names, SSNs, addresses, DOB, diagnoses, and insurance data. CodeMetro acted as a Business Associate. Response included notifying HHS, individuals, and media, workforce retraining, and implementation of technical safeguards.
- 🦬Montana State AGas victim2020-06-19
CodeMetro reported a data breach to the Montana Attorney General. The breach was reported on 2020-06-19. The breach occurred on 4/21/2020.
- 🐻California State AGas victim2020-06-16
CodeMetro, a provider of software solutions to applied behavior analysis providers, suffered a ransomware attack on April 21, 2020. The attackers accessed a database server, copied and removed health-related patient information including names, contact details, school information, insurance data, and medical records. CodeMetro contained the threat, engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring to affected individuals.