DataStat, Inc. Data Breach
DataStat, Inc. Unauthorized Access to Patient Records
What happened in the DataStat, Inc. data breach?
The DataStat, Inc. data breach was reported on August 8, 2022 and affected 1,650 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in Michigan. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
DataStat, Inc. Breach Details
DataStat, Inc. Healthcare Data Breach Report
Incident Overview
DataStat, Inc., a healthcare data management company operating in Michigan, experienced an unauthorized access and disclosure incident affecting 1,650 individuals. The breach was reported to the U.S. Department of Health and Human Services on August 8, 2022. The unauthorized access involved physical records stored in paper and film formats, representing a significant deviation from typical digital breach incidents. This breach demonstrates that healthcare data security vulnerabilities extend beyond networked systems to include physical document storage and handling procedures.
Discovery and Response Timeline
While specific discovery details are not provided in the breach submission, DataStat, Inc. initiated a formal investigation upon identifying the unauthorized access. The entity's response included a comprehensive review of affected records and implementation of notification procedures required under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule. The August 8, 2022 submission date indicates the breach was reported within the regulatory timeframe, suggesting the entity discovered the incident and completed its investigation within a reasonable period. As a business associate, DataStat, Inc. was obligated to notify its covered entity clients, who in turn were responsible for notifying affected individuals.
Breach Mechanism and Physical Security Details
Specific Details
The breach involved unauthorized access to paper and film-based records, which typically indicates either physical theft, unauthorized employee access, or inadequate physical security controls at storage facilities. Paper and film records require different security protocols than electronic systems—including restricted access areas, inventory controls, and secure disposal procedures. The location designation suggests records may have been stored in filing systems, archives, or microfilm repositories that were either improperly secured or monitored. Unauthorized access to physical records can occur through multiple vectors: an employee with legitimate access exceeding their authorization scope, a third party gaining entry to restricted areas, or inadequate segregation of sensitive materials from general office spaces.
Physical document breaches often go undetected longer than digital breaches because they lack the audit trails and access logs inherent to electronic systems. The fact that this breach involved 1,650 individuals suggests a systematic access event rather than isolated document loss—potentially indicating a period of unauthorized access or a single large-scale removal of records.
Organizational Context
DataStat, Inc. operates as a healthcare data management and analysis company, functioning as a business associate under HIPAA regulations. Business associates are entities that handle protected health information (PHI) on behalf of covered entities such as hospitals, clinics, and health plans. DataStat's role likely involves data processing, analysis, storage, or reporting services for multiple healthcare organizations across Michigan and potentially beyond. The company's involvement with paper and film records suggests it may maintain historical archives, legacy data systems, or specialized data repositories that require long-term retention. The presence of physical records in a data management company's facilities indicates either archival functions, document imaging operations, or transition services involving legacy systems.
Patient Impact and Affected Population
Number of People Affected
Approximately 1,650 individuals had their protected health information potentially exposed through unauthorized access. This population size places the breach in the medium-severity category, though the sensitivity of exposed data types elevates the overall risk profile. The affected individuals likely span multiple healthcare organizations that contracted with DataStat, Inc., meaning notification responsibilities were distributed across multiple covered entities.
Personal Information Involved
While the specific data elements are not detailed in the breach submission, individuals whose records were stored with DataStat, Inc. likely had the following information potentially exposed:
- Full names and contact information (addresses, phone numbers, email addresses)
- Date of birth and age information
- Medical record numbers and patient identification numbers
- Healthcare provider names and facility information
- Diagnosis codes and clinical information
- Treatment history and medication records
- Insurance information and policy numbers
- Social Security numbers (if included in medical records)
- Financial information related to healthcare billing
The specific combination of exposed data depends on what information was included in the paper and film records accessed without authorization.
HIPAA Compliance and Notification Requirements
Under the HIPAA Breach Notification Rule, DataStat, Inc. as a business associate was required to notify affected covered entities without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. Covered entities then had responsibility for notifying affected individuals, the media (if more than 500 residents were affected in a jurisdiction), and the HHS Secretary. The August 8, 2022 submission date represents DataStat's notification to HHS, which typically occurs after individual notifications have been sent. This breach type—unauthorized access to physical records—is increasingly common as healthcare organizations maintain hybrid paper-electronic systems and manage legacy data archives.
Recommended Actions for Affected Individuals
Individuals whose information may have been exposed should take the following protective measures:
-
Monitor Credit Reports and Financial Accounts: Obtain free credit reports from all three major bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and review for unauthorized accounts or inquiries. Set up fraud alerts with credit bureaus and consider credit freezes to prevent unauthorized credit applications.
-
Review Medical Records and Billing Statements: Request copies of medical records from all healthcare providers to verify accuracy and identify any unauthorized access or fraudulent services. Review explanation of benefits (EOB) statements and medical bills for unfamiliar charges or services not received.
-
Implement Identity Theft Protection: Consider enrolling in credit monitoring services, which may be offered by DataStat, Inc. or the affected covered entities. Monitor for suspicious activity including unexpected medical bills, collection notices, or insurance claims for services not received.
-
Report Suspicious Activity Immediately: If unauthorized use of personal information is discovered, file a report with the Federal Trade Commission (FTC) at IdentityTheft.gov, contact local law enforcement, and notify affected healthcare providers and insurance companies immediately to prevent further unauthorized access.
Severity and Visibility Assessment
Severity Band: Medium
This breach is classified as medium severity due to the combination of 1,650 affected individuals and the likely exposure of sensitive health information. While the number of affected individuals falls below the 10,000 threshold for high severity, the nature of healthcare data—which includes diagnosis, treatment, and potentially financial information—elevates the risk profile. Unauthorized access to medical records creates significant potential for identity theft, medical fraud, and privacy violations.
Visibility Band: Regional
The breach has regional significance due to DataStat, Inc.'s operations in Michigan and the involvement of a business associate serving multiple healthcare organizations. While not a national-scale incident, the breach affects multiple covered entities and their patient populations across a state or multi-state region, warranting regional attention and awareness.
Technical and Operational Notes
Physical record breaches present unique challenges compared to digital incidents. Paper and film records lack the encryption, access controls, and audit logging available for electronic systems. The breach likely resulted from inadequate physical security measures such as insufficient access restrictions, lack of inventory controls, or inadequate employee training regarding document handling. Organizations maintaining physical healthcare records must implement controls including: restricted access to storage areas, visitor logs, employee background checks, regular inventory audits, secure destruction procedures, and employee training on confidentiality obligations. The involvement of a business associate adds complexity to breach response, as multiple organizations must coordinate notification efforts and remediation activities.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the DataStat, Inc. Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) at AnnualCreditReport.com and place fraud alerts or credit freezes to prevent unauthorized credit applications
Review medical records and billing statements from all healthcare providers for unauthorized services or fraudulent charges, and request copies of records to verify accuracy
Enroll in credit monitoring services if offered by DataStat, Inc. or affected healthcare providers, and monitor for suspicious activity including unexpected medical bills or collection notices
Report any discovered unauthorized use to the FTC at IdentityTheft.gov, local law enforcement, and affected healthcare providers immediately to prevent further unauthorized access
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Michigan Breaches
Search all breaches reported in Michigan