Skip to content

AAA Collections

Disclosed Nov 16, 20223 years ago56,848 affectedConfirmed

Official notice

The business associate (BA), AAA Collections, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 4,635 individuals. The PHI involved included names, addresses, dates of birth, medical record numbers, diagnoses, financial information, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional administrative, technical, and security safeguards. Identity theft protection services were also provided.

What is known

People affected56,848 (as reported by the organization)
DisclosedNov 16, 2022
HappenedSep 5, 2022
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2022 data breach report: AAA Collectionsin.gov · Official notice
HHS OCR breach report (archive, resolved): AAA Collections (Business Associate, SD)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INNov 16, 202258
HHS archivetotalDec 15, 20224,635
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), AAA Collections, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 4,635 individuals. The PHI involved included names, addresses, dates of birth, medical · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about AAA Collections

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.