Perry Johnson & Associates
ent_d0b5b42c069c75b87305b3db
Disclosures
12
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
13,300,750
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Perry Johnson & Associates
- Normalized
- perry johnson associates— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- Massachusetts State AGas victim2024-02-09
Perry Johnson & Associates, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-09. 39,064 Massachusetts residents were affected.
- Maine State AGas victim2024-02-08
Perry Johnson & Associates, Inc. (PJ&A), a medical transcription services company, reported a data breach impacting 42,220 Maine residents. An unauthorized party gained access to its systems between March 27, 2023, and May 2, 2023. The breach was discovered on May 2, 2023, with the involvement of Protected Health Information (PHI) confirmed on May 22, 2023. The compromised data includes names and Social Security Numbers. The company provided notice to affected individuals and offered at least 12 months of identity theft protection services.
- New Hampshire State AGas victim2024-02-08
Perry Johnson & Associates (PJ&A), a medical transcription vendor, experienced unauthorized access to systems containing patient information for Concentra Health Services between March 27 and May 2, 2023. PJ&A detected suspicious activity on May 2, 2023. The breach impacted PHI and PII. PJ&A engaged third-party cybersecurity specialists and offered credit monitoring to affected individuals.
- California State AGas reporting2024-02-05
Perry Johnson & Associates, a vendor to The South Bend Clinic, LLC, notified patients of a data security incident. Unauthorized third-party access to PJ&A systems occurred between April 7 and April 19, 2023, impacting personal health information including names. PJ&A became aware of the incident on May 2, 2023. The investigation determined that Social Security numbers were not impacted. PJ&A retained cybersecurity vendors, notified law enforcement, and implemented additional security measures.
- South Carolina State AGas victim2023-11-06
Perry Johnson & Associates, Inc. notified South Carolina of a data breach where unauthorized third-party access to systems occurred between March 27 and May 2, 2023. The incident impacted personal health information (PHI) including names, DOBs, SSNs, and medical records. The company engaged forensic vendors, reset passwords, and notified HHS.
- California State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A), a healthcare transcription service provider and HIPAA business associate, experienced unauthorized access to personal health information (PHI) between April 7 and April 19, 2023. The incident was discovered on May 2, 2023. Affected data included names, dates of birth, addresses, medical record numbers, diagnoses, and potentially Social Security numbers and clinical information. PJ&A engaged external cybersecurity vendors, notified law enforcement and HHS, and implemented technical restrictions and password resets. No evidence of identity theft or fraud was identified at the time of notification.
- Massachusetts State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A) reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-03. 6,219 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas reporting2023-11-03
PJ&A filed a supplemental Washington AG notice for a breach affecting Concentra, Inc. patients. Unauthorized access occurred March 27-May 2, 2023 via compromised RDS credentials. Data included PHI, SSNs, and financial info. 22,088 individuals affected; 21,075 in WA. Notices mailed Nov 3, 2023.
- New Hampshire State AGas reporting2023-11-03
Perry Johnson & Associates (PJ&A), a medical transcription vendor, reported a data breach affecting Northwell Health, Crouse Health, and CarePoint Health. Unauthorized access occurred March 27–May 2, 2023, via compromised RDS credentials. The actor demanded ransom and exfiltrated PHI and PII. 867 New Hampshire residents were notified on November 3, 2023, with credit monitoring offered. PJ&A engaged forensic investigators and law enforcement.
- NEVADAHHS OCRas victim2023-11-03
Perry Johnson & Associates, Inc. dba PJ&A reported to HHS on 2023-11-03 a Hacking/IT Incident affecting 9,302,588 individuals. Breached information located on Network Server. The incident involved a ransomware attack compromising PHI including names, SSNs, and medical data.
- Montana State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A), a medical transcription service provider, disclosed a data breach where unauthorized third parties accessed systems between March 27 and May 2, 2023. The incident impacted personal health information (PHI) and PII of patients. PJ&A engaged forensic vendors, reset passwords, and notified HHS and law enforcement.
- Oregon State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A) reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-03. The breach occurred during 3/27/2023 - 5/2/2023. The breach was discovered on 5/22/202310/12/2023. 3,891,565 individuals were affected. Notice was sent on 11/3/2023.