PJ&A transcription breach exposed data of nearly 9 million patients
- Organization
- Perry Johnson & Associates (PJ&A)
- Exploit
- Hacking
- Industry
- Medical Transcription
Perry Johnson & Associates, a Henderson, Nevada firm that turns physician dictation into medical records, was breached by an intruder who sat on its network between March 27 and May 2, 2023. PJ&A said files were actually accessed during a narrower window in April. Its investigation closed on September 28, 2023, and notification letters went out from November 3.
Because PJ&A works as a business associate for hospitals and health systems, the exposure cascaded across its client base. The firm reported 8,952,212 individuals to the U.S. Department of Health and Human Services Office for Civil Rights, placing the incident among the largest healthcare data breaches disclosed in the United States.
Exposed information varied by client and included names, addresses, dates of birth, medical record and hospital account numbers, admission diagnoses, dates of service, clinical details drawn from transcribed files and, for some patients, Social Security numbers and insurance information.
Cook County Health in Illinois said 1.2 million of its patients were affected. It stopped sharing data with PJ&A and terminated the business associate agreement, and said it did not receive a final list of affected patients until October 9, 2023. Northwell Health in New York circulated a draft figure of 3,891,565 people, then withdrew it and said it could not confirm a number.