Skip to content

FastHealth

Disclosed May 26, 20179 years ago18,192 affectedConfirmed

Official notice

FastHealth Corporation, a business associate (BA), reported that it was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of 18,192 individuals. The ePHI involved included names, addresses, dates of birth, drivers’ license information, Social Security numbers, financial information, diagnoses, and medications prescribed. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its ePHI. The BA notified HHS, affected individuals, and the media. OCR provided the BA with technical assistance regarding the HIPAA Breach Notification Rule.

What is known

People affected18,192 (as reported to HHS)
DisclosedMay 26, 2017
DiscoveredNov 2, 2017
HappenedAug 14, 2017
AttackHacking
Data exposedNames, Social Security numbers, Government IDs, Payment cards, Financial, Passwords, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: FastHealthoag.ca.gov · Official notice
Washington Attorney General breach notice: FastHealthatg.wa.gov · Official notice
Oregon DOJ breach notice: FastHealthjustice.oregon.gov · Official notice
Maine Attorney General breach notice archive: FastHealthmaine.gov · Official notice
HHS OCR breach report (archive, resolved): FastHealth (Business Associate, AL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAMay 26, 2017
Maine AGresidents of MEMay 26, 201714
HHS archivetotalJun 29, 201718,192
California AGresidents of CAFeb 27, 2018
Washington AGresidents of WAFeb 27, 20182,876
Oregon DOJresidents of ORFeb 27, 2018657,529
Maine AGresidents of MEFeb 27, 2018881
HHS archivetotalFeb 27, 201818,192
History of this record
  • 2026-09-25 · data_types: ["names","ssn","government-id","payment-card","financial","passwords"] to ["names","ssn","government-id","payment-card","financial","passwords","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 18192 · backfill source
  • 2026-09-25 · summary: empty to FastHealth Corporation, a business associate (BA), reported that it was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of 18,192 individuals. The ePHI involved included names, addresses, dates · backfill source
  • 2026-09-25 · data_types: [] to ["names","ssn","government-id","payment-card","financial","passwords"] · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2017-11-02 · backfill source
  • 2026-09-25 · disclosed: 2018-02-27 to 2017-05-26 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about FastHealth

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.