GRM Information Management Services
ent_db7e4597070cd2d47d6c71a7
Disclosures
2
State AG · HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1,700,000
nationwide · HHS OCR NJ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GRM Information Management Services
- Normalized
- grm information management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- Massachusetts State AGas victim2023-02-02
GRM Information Management Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-02-02. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- NEW JERSEYHHS OCRas victim2011-02-11
Unencrypted clinical system backup tapes containing ePHI of 1,700,000 individuals were stolen from an unlocked vehicle belonging to an employee of GRM Information Management Services, a business associate of the covered entity. ePHI included names, MRNs, SSNs, addresses, phone numbers, health plan numbers, dates of birth/admission/treatment/discharge/death, mother's name, next of kin, and clinical information (diagnoses, treatment, prognosis, lab results, medications). The covered entity filed a police report, notified HHS, media, and affected individuals, terminated the BA agreement, and installed encryption software on backup media following OCR's investigation. Incident occurred prior to the September 23, 2013 HIPAA Omnibus compliance date.