Perry Johnson & Associates
ent_d0b5b42c069c75b87305b3db
Disclosures
7
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
3,891,565
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Perry Johnson & Associates
- Normalized
- perry johnson associates— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🦞Maine State AGas victim2024-02-08
Perry Johnson & Associates, Inc. (PJ&A), a medical transcription services company, reported a data breach impacting 42,220 Maine residents. An unauthorized party gained access to its systems between March 27, 2023, and May 2, 2023. The breach was discovered on May 2, 2023, with the involvement of Protected Health Information (PHI) confirmed on May 22, 2023. The compromised data includes names and Social Security Numbers. The company provided notice to affected individuals and offered at least 12 months of identity theft protection services.
- ⛰️New Hampshire State AGas victim2024-02-08
Perry Johnson & Associates (PJ&A), a medical transcription vendor, experienced unauthorized access to systems containing patient information for Concentra Health Services between March 27 and May 2, 2023. PJ&A detected suspicious activity on May 2, 2023. The breach impacted PHI and PII. PJ&A engaged third-party cybersecurity specialists and offered credit monitoring to affected individuals.
- 🐻California State AGas reporting2024-02-05
Perry Johnson & Associates, a vendor to The South Bend Clinic, LLC, notified patients of a data security incident. Unauthorized third-party access to PJ&A systems occurred between April 7 and April 19, 2023, impacting personal health information including names. PJ&A became aware of the incident on May 2, 2023. The investigation determined that Social Security numbers were not impacted. PJ&A retained cybersecurity vendors, notified law enforcement, and implemented additional security measures.
- 🐻California State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A), a healthcare transcription service provider and HIPAA business associate, experienced unauthorized access to personal health information (PHI) between April 7 and April 19, 2023. The incident was discovered on May 2, 2023. Affected data included names, dates of birth, addresses, medical record numbers, diagnoses, and potentially Social Security numbers and clinical information. PJ&A engaged external cybersecurity vendors, notified law enforcement and HHS, and implemented technical restrictions and password resets. No evidence of identity theft or fraud was identified at the time of notification.
- 🌲Washington State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A), a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-02 and filed notice on 2023-11-03. 22,088 Washington residents were affected. 185 days elapsed between awareness and notification. 36 days to identify the breach. 0 days to contain the breach.
- ⛰️New Hampshire State AGas reporting2023-11-03
Perry Johnson & Associates (PJ&A), a medical transcription vendor, reported a data breach affecting Northwell Health, Crouse Health, and CarePoint Health. Unauthorized access occurred March 27–May 2, 2023, via compromised RDS credentials. The actor demanded ransom and exfiltrated PHI and PII. 867 New Hampshire residents were notified on November 3, 2023, with credit monitoring offered. PJ&A engaged forensic investigators and law enforcement.
- 🦫Oregon State AGas victim2023-11-03
Perry Johnson & Associates, Inc. (PJ&A) reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-03. The breach occurred during 3/27/2023 - 5/2/2023. The breach was discovered on 5/22/202310/12/2023. 3,891,565 individuals were affected. Notice was sent on 11/3/2023.