QRS, Inc., a software provider for medical practices, experienced unauthorized access to a patient portal server from August 23-26, 2021. An unknown third party accessed and potentially acquired PHI, including names, SSNs, and medical data. Gregory Brewer, MD PLLC, a business associate, notified one New Hampshire resident on October 22, 2021. QRS took the server offline, engaged forensic investigators, and implemented MFA and SIEM.
Affected (this filing): 1