Skip to content

Med-Cert

Disclosed Sep 1, 20179 years ago7,253 affectedConfirmed

Official notice

On July 7, 2017, Med-Cert, Inc., a business associate (BA) for multiple health plans, learned that protected health information (PHI) was publically accessible through several online search engines including Bing and Google. The exposed PHI included the names, addresses, birthdates, employer information, and case management reports for 7,243 individuals, as well as some social security numbers. The BA provided breach notification to HHS and the affected individuals in a timely and compliant manner. No media or substitute notice was required. Following the breach, the BA discovered that the exposure was caused by a subcontractor, Alentus Hosting, which failed to reactivate a firewall after a software update. As a result, “web-crawlers” infiltrated the subcontractor’s computer network, stole electronic PHI, and posted it online. In response to the breach, the BA immediately contacted the subcontractor and had them close the vulnerability. The BA and the subcontractor did not have a BA agreement (BAA) in place. As a result of the breach, the subcontractor ceased responding to the BA’s request for information. The BA ended its business relationship with the subcontractor and acquired t

What is known

People affected7,253 (as reported to HHS)
DisclosedSep 1, 2017
HappenedJun 17, 2017
AttackHacking
Data exposedNames, Social Security numbers, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2017 data breach report: Med-Certin.gov · Official notice
Maine Attorney General breach notice archive: Med-Certmaine.gov · Official notice
HHS OCR breach report (archive, resolved): Med-Cert (Business Associate, FL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INSep 1, 20172,592
Maine AGresidents of MESep 1, 2017210
HHS archivetotalSep 2, 20177,253
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 7237 to 7253 · backfill source
  • 2026-09-25 · summary: empty to On July 7, 2017, Med-Cert, Inc., a business associate (BA) for multiple health plans, learned that protected health information (PHI) was publically accessible through several online search engines including Bing and Google. The exposed PHI · backfill source
  • 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Med-Cert

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.