Med-Cert
Disclosed Sep 1, 20179 years ago7,253 affectedConfirmed
On July 7, 2017, Med-Cert, Inc., a business associate (BA) for multiple health plans, learned that protected health information (PHI) was publically accessible through several online search engines including Bing and Google. The exposed PHI included the names, addresses, birthdates, employer information, and case management reports for 7,243 individuals, as well as some social security numbers. The BA provided breach notification to HHS and the affected individuals in a timely and compliant manner. No media or substitute notice was required. Following the breach, the BA discovered that the exposure was caused by a subcontractor, Alentus Hosting, which failed to reactivate a firewall after a software update. As a result, “web-crawlers” infiltrated the subcontractor’s computer network, stole electronic PHI, and posted it online. In response to the breach, the BA immediately contacted the subcontractor and had them close the vulnerability. The BA and the subcontractor did not have a BA agreement (BAA) in place. As a result of the breach, the subcontractor ceased responding to the BA’s request for information. The BA ended its business relationship with the subcontractor and acquired t
What is known
| People affected | 7,253 (as reported to HHS) |
|---|---|
| Disclosed | Sep 1, 2017 |
| Happened | Jun 17, 2017 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2017 data breach report: Med-Certin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Med-Certmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Med-Cert (Business Associate, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Sep 1, 2017 | 2,592 |
| Maine AGresidents of ME | Sep 1, 2017 | 210 |
| HHS archivetotal | Sep 2, 2017 | 7,253 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 7237 to 7253 · backfill source
- 2026-09-25 · summary: empty to On July 7, 2017, Med-Cert, Inc., a business associate (BA) for multiple health plans, learned that protected health information (PHI) was publically accessible through several online search engines including Bing and Google. The exposed PHI · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.