QRS
Disclosed Oct 22, 20214 years ago430,334 affectedConfirmed
QRS, the business associate (BA), reported that it experienced a hacking attack that compromised the protected health information (PHI) of 430,334 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, lab results, and medications. The BA notified HHS, affected individuals, the media, and published substitute notice on its homepage. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards. OCR provided technical assistance regarding the HIPAA Rules.
What is known
| People affected | 430,334 (as reported to HHS) |
|---|---|
| Disclosed | Oct 22, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): QRS (Business Associate, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 22, 2021 | 430,334 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.