Health Quest Systems, Inc.
ent_cc2fc2917d1f450a4e2badb0
Disclosures
5
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
372,043
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Health Quest Systems, Inc.
- Normalized
- health quest— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Massachusetts State AGas victim2020-01-10
Health Quest Systems, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-01-10. 138 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2020-01-10
Health Quest Systems, Inc. notified patients of a phishing incident where employee credentials were compromised, leading to unauthorized access to email accounts containing PHI, SSNs, and financial data. The incident was first detected in July 2018, with the investigation concluding in November 2019. Affected individuals received one year of credit monitoring.
- California State AGas victim2020-01-10
Health Quest Systems, Inc. experienced a phishing incident in July 2018 where employees were tricked into disclosing email credentials. An unauthorized party accessed these accounts. A comprehensive review completed in November 2019 determined that patient information, including names, SSNs, driver's license numbers, passport numbers, financial account info, health insurance info, and clinical data, may have been exposed. The company secured accounts, engaged forensic investigators, and is offering credit monitoring. Remediation includes MFA and security training.
- Illinois State AGas victim2020-01-01
HEALTH QUEST SYSTEMS filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-007). The register records the breach as discovered on October 25, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NEW YORKHHS OCRas victim2019-05-31
Health Quest Systems, Inc. reported to HHS on 2019-05-31 a Hacking/IT Incident affecting 372,043 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing ePHI including names, SSNs, driver's license numbers, financial information, and treatment data.