AAA Collections
Disclosed Nov 16, 20223 years ago56,848 affectedConfirmed
The business associate (BA), AAA Collections, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 4,635 individuals. The PHI involved included names, addresses, dates of birth, medical record numbers, diagnoses, financial information, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional administrative, technical, and security safeguards. Identity theft protection services were also provided.
What is known
| People affected | 56,848 (as reported by the organization) |
|---|---|
| Disclosed | Nov 16, 2022 |
| Happened | Sep 5, 2022 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2022 data breach report: AAA Collectionsin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): AAA Collections (Business Associate, SD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Nov 16, 2022 | 58 |
| HHS archivetotal | Dec 15, 2022 | 4,635 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The business associate (BA), AAA Collections, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 4,635 individuals. The PHI involved included names, addresses, dates of birth, medical · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.