Skip to content

Advanced Data Processing

Disclosed Nov 28, 201213 years ago10,000 affectedConfirmed

Official notice

On or around June 15, 2012, an employee of the covered entity (CE), Advanced Data Processing, Inc. (ADP), dba Intermedix, who had access to patients’ protected health information (PHI) as part of her job, inappropriately accessed the PHI of approximately 10,000 individuals and sold the information to third parties. An addendum to the initial breach report, submitted on April 3, 2015, expanded the breach to an additional 2,360 individuals. The PHI involved in the breach included patient names, social security numbers, addresses, dates of birth, claims, and other financial information. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice. Following the breach, the CE engaged a third party to review its network environment and make recommendations for security enhancements. It implemented data loss prevention technology to identify electronic PHI and block transmittal of sensitive information and a log management and analysis solution to automate collection, analysis, archival and recovery of log data. The CE implemented policies and procedures for disposal and reuse of mobile devices, as well as for the secure transport of sensi

What is known

People affected10,000 (as reported to HHS)
DisclosedNov 28, 2012
HappenedJun 15, 2012
AttackLost or stolen device
Data exposedNames, Health
SectorTech · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CANov 28, 2012
HHS archivetotalNov 29, 201210,000

Other breaches at Advanced Data Processing

BreachAffected
Disclosed Oct 8, 2014Oct 8, 201411 years agoUnknown
History of this record
  • 2026-09-25 · attack: unknown to lost-device · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 10000 · backfill source
  • 2026-09-25 · summary: empty to On or around June 15, 2012, an employee of the covered entity (CE), Advanced Data Processing, Inc. (ADP), dba Intermedix, who had access to patients’ protected health information (PHI) as part of her job, inappropriately accessed the PHI of · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Advanced Data Processing

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.