Cogent Healthcare, Inc. disclosed a security lapse involving third-party vendor M2ComSys, a medical transcription company. Between May 5, 2013, and June 24, 2013, unauthorized parties accessed patient care notes containing PHI, including patient names, DOBs, diagnoses, and medical record numbers. No Social Security numbers or copies of medical records were included. Cogent ended its relationship with M2, recovered hardware, and worked with Google to remove indexed PHI. Affected individuals were offered one year of Experian’s ProtectMyID credit monitoring and fraud resolution services.