DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

PA: Partners for Quality notifies 3,673 clients after employee email accounts compromised

Posted on April 25, 2019 by Dissent

Pennsylvania-based Partners for Quality is an agency focused on providing services to children with intellectual and developmental disabilities who face behavioral health challenges.  PFQ consists of four entities:

  • Allegheny Children’s Initiative
  • Citizen Care
  • Lifeways, Inc. d/b/a Exceptional Adventures
  • Milestone Centers, and
  • Partners For Quality Foundation

More information about the programs can be found on their web site.

[Note: this is not the same “Milestone” that reported a breach in March. And it is not clear from their notification, described below, whether the breach impacted all four of the entities above or just one of them or some of them.]

On April 19, PFQ posted a notice on their web site and notified HHS that 3,673 clients were being notified of an incident that PFQ discovered on February 19, when they became aware of unusual activity related to some employees’ email accounts. Third-party investigators subsequently determined that unauthorized individuals had access to three employees’ accounts between January 19, 2019 and February 27, 2019.  Those email accounts contained protected health information and certain employee information: name, date of birth, Social Security number, diagnosis or treatment information, medical record number, billing/claims information, health insurance information, driver’s license number, passport information, banking or financial account number, credit / debit card information, PIN number, and username and password.

As of April 19, PFQ had not received any reports of the misuse of this information. Somewhat surprisingly, however, they do not seem to be offering those affected any monitoring assistance or services – or  if they are, they are not mentioning that specifically in their public disclosure.

You can read their full notification on their site.

 

Category: Health DataPhishingU.S.

Post navigation

← Greek DPA Issues EUR 30,000 Fine For Data Protection Violation by Hellenic Petroleum S.A.
Safeguard your network and customer credentials: Tips from the latest FTC data security case →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.