Data leak
Ambulance Billing Firm $515K State AG Settlement β Massachusetts and Indiana Hack
Primary Source βIncident Details
An ambulance billing and medical collections firm agreed to pay $515,000 to Massachusetts and Indiana
attorneys general following a hack that compromised patient data. The firm provided revenue cycle management
services for ambulance providers, storing patient names, dates of service, insurance information, and
potentially Social Security numbers and treatment data. The settlement required the firm to implement enhanced
cybersecurity controls including encryption, MFA, and employee training. Multi-state enforcement actions
against healthcare vendors for data security failures are increasingly common following major HHS OCR
settlements.
Technical Details
- Initial Attack Vector
- Unknown attacker compromised ambulance billing and collections firm systems accessing patient data
Timeline
- 2026-01-29 Breach occurred
- 2026-01-29 Publicly disclosed