Inmediata Health Group
ent_e900ea1636621eb7b61e2799
Disclosures
5
HHS OCR enforcement · State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,565,338
nationwide · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Inmediata Health Group
- Normalized
- inmediata health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- FEDERALHHS OCR enforcementas victim2024-12-10
HHS OCR settled with Inmediata Health Group, LLC, a health care clearinghouse, for $250,000 over HIPAA Security Rule failures. From May 2016 to January 2019, PHI of 1,565,338 individuals was publicly accessible online due to lack of risk analysis and monitoring. The settlement resolves OCR's investigation.
- Oregon State AGas victim2019-06-03
Inmediata Health Group, Corp reported a data breach to the Oregon Attorney General. The breach was reported on 2019-06-03. The breach occurred during 1/1/2019. The breach was discovered on 1/1/2019. Notice was sent on 4/22/2019.
- FEDERALHHS OCRas victim2019-05-07
Inmediata Health Group, LLC (Healthcare Clearing House) reported to HHS OCR on 2019-05-07 an Unauthorized Access/Disclosure affecting 1,565,338 individuals. PHI — including patient names, dates of birth, home addresses, Social Security numbers, claims information, and diagnosis/treatment data — was left publicly accessible on a Network Server and indexed by internet search engines from May 2016 through January 2019. OCR found failures in risk analysis and system-activity monitoring. Inmediata paid a $250,000 settlement; a separate 33-state AG settlement addressed corrective actions.
- California State AGas victim2019-04-30
Inmediata Health Group, Corp. disclosed that in January 2019, patient health information was publicly available online due to a webpage setting that permitted search engines to index internal business operation pages. The exposed data included names, addresses, dates of birth, gender, and medical claim information (diagnosis/procedure codes). For some individuals, Social Security numbers were also exposed. The company deactivated the website, engaged forensic investigators, and removed indexed data from search engines. No evidence of data copying or misuse was found.
- Montana State AGas victim2019-04-30
Inmediata Health Group notified patients in January 2019 that a webpage misconfiguration allowed search engines to index an internal site, exposing patient health information and personal data. The company deactivated the site, engaged forensic investigators, and offered one year of identity monitoring. No evidence of data misuse was found.