Professional Finance Company, Inc. Data Breach
Professional Finance Company Network Breach Affects 1.9M
What happened in the Professional Finance Company, Inc. data breach?
The Professional Finance Company, Inc. data breach was reported on July 1, 2022 and affected 1,918,941 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Colorado. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Professional Finance Company, Inc. Breach Details
Professional Finance Company Data Breach Report
Opening Summary
Professional Finance Company, Inc., a Colorado-based healthcare financial services organization, experienced a significant data breach involving unauthorized access to its network servers. The breach was reported to the Colorado Attorney General on July 1, 2022, and potentially compromised the protected health information (PHI) and personal financial data of approximately 1.9 million individuals. The breach occurred through a hacking or IT incident targeting the company's network infrastructure, representing one of the larger healthcare-related data breaches reported in 2022. As a business associate to covered entities under HIPAA, Professional Finance Company was responsible for maintaining safeguards over sensitive patient information, making this breach a matter of significant regulatory and consumer concern.
Company Response and Investigation
Upon discovery of the unauthorized network access, Professional Finance Company initiated an incident response protocol consistent with HIPAA breach notification requirements. The company conducted a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what categories of information may have been accessed or exfiltrated. The investigation process typically involves forensic analysis of network logs, access controls, and system activity to establish the timeline of the intrusion and the extent of data exposure. Professional Finance Company notified affected individuals and relevant regulatory authorities as required under the HIPAA Breach Notification Rule, which mandates notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The company also likely engaged third-party cybersecurity experts to conduct forensic investigations and determine the root cause of the network compromise.
Technical Details of the Breach
The breach involved unauthorized access to the company's network server infrastructure, which typically serves as the central repository for patient records, financial information, and operational data. Network server breaches of this magnitude generally indicate either exploitation of unpatched vulnerabilities, compromise of administrative credentials, or successful phishing attacks that provided attackers with initial network access. The scale of the breach—affecting nearly 1.9 million individuals—suggests the attackers maintained access to core systems for a period of time sufficient to identify and extract large volumes of data. Hacking incidents targeting healthcare financial services companies often involve sophisticated threat actors seeking valuable personal and financial information that can be monetized through identity theft, fraudulent billing, or sale on dark web marketplaces. The fact that this was classified as a network server breach indicates the compromise was not limited to a single workstation or isolated system, but rather affected centralized infrastructure where large datasets are stored and processed.
Organizational Context
Professional Finance Company, Inc. operates as a healthcare business associate, meaning it provides financial services, billing, claims processing, or related administrative functions on behalf of covered entities such as hospitals, physician practices, and health plans. As a business associate, the company was contractually obligated to implement and maintain administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule. The company's Colorado headquarters and operations suggest it may serve healthcare providers and patients across the Rocky Mountain region and potentially nationwide. Business associates in the healthcare financial services sector typically handle sensitive information including patient names, dates of birth, Social Security numbers, insurance information, medical record numbers, and financial account details. The breach of a business associate's systems is particularly concerning because it affects not just the company's direct customers, but the millions of patients whose information those customers entrusted to the business associate for processing.
Impact on Affected Individuals
Approximately 1,918,941 individuals were notified of potential exposure to their personal and health information as a result of this breach. This represents one of the larger healthcare data breaches in terms of affected population, placing it in the national significance category. Affected individuals likely include patients of multiple healthcare providers who utilized Professional Finance Company's services for billing, claims processing, or financial management. The breach notification process required the company to provide affected individuals with details about the breach, the types of information exposed, steps the company was taking to address the incident, and recommended actions for individuals to protect themselves. Individuals affected by this breach may have had multiple categories of sensitive information exposed, creating compounded risk for identity theft and fraud. The notification timeline and methods used (mail, email, or phone) would have been determined by the company's breach response procedures and regulatory requirements.
Data Exposure and Risk Assessment
While the specific data elements exposed were not detailed in the breach submission, individuals affected by a network server breach at a healthcare financial services company typically face exposure of multiple sensitive data categories. These likely include: full names, dates of birth, Social Security numbers, health insurance information including member IDs and group numbers, medical record numbers, financial account information, banking details, diagnosis codes, treatment information, and potentially prescription data. The combination of health information with financial and identifying data creates elevated risk for identity theft, fraudulent account creation, unauthorized medical services, and insurance fraud. Individuals may be vulnerable to phishing attacks using their healthcare information as social engineering hooks, and their financial accounts may be targeted for unauthorized access or fraudulent transactions.
HIPAA Compliance and Regulatory Context
This breach represents a failure of the HIPAA Security Rule requirements that Professional Finance Company, as a business associate, was obligated to meet. The Security Rule requires covered entities and business associates to implement safeguards including access controls, encryption, audit controls, and integrity controls to protect ePHI (electronic protected health information). Network server breaches of this scale typically indicate deficiencies in one or more of these areas—such as inadequate access controls, failure to implement encryption, insufficient monitoring of network activity, or delayed patching of known vulnerabilities. The breach notification to the Colorado Attorney General and affected individuals was required under the HIPAA Breach Notification Rule, which applies when unsecured PHI is accessed or acquired by unauthorized persons. Healthcare data breaches involving network infrastructure compromises have become increasingly common, with attackers targeting healthcare organizations due to the high value of health information and the critical nature of healthcare operations, which may increase likelihood of ransom payment in ransomware scenarios.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Professional Finance Company, Inc. Breach
Place a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) by contacting one bureau, which will notify the others. A fraud alert requires creditors to verify your identity before opening new accounts in your name.
Consider placing a credit freeze with all three credit bureaus to prevent unauthorized access to your credit file. While this requires more steps to unfreeze when you need credit, it provides stronger protection than a fraud alert.
Monitor your credit reports regularly for suspicious activity by obtaining free annual credit reports from www.annualcreditreport.com and reviewing them for accounts or inquiries you did not authorize.
Monitor your financial accounts and healthcare claims for unauthorized activity. Review bank and credit card statements monthly, and request an Explanation of Benefits (EOB) from your health insurance to verify that only authorized services were billed.
Change passwords for all online accounts, particularly healthcare provider portals, insurance company accounts, and financial institution accounts. Use strong, unique passwords for each account.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions. Verify any requests for information by contacting the organization directly using a phone number or website you know to be legitimate.
Consider enrolling in credit monitoring or identity theft protection services, which may be offered free by Professional Finance Company as part of their breach response. These services can alert you to suspicious activity.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you discover evidence of identity theft or fraud. This creates an official record and provides a recovery plan.
Contact your health insurance company and healthcare providers to inform them of the breach and request that they monitor your accounts for fraudulent activity.
Retain copies of all breach notification letters and documentation of any fraudulent activity for your records, as you may need this information for credit disputes or insurance claims.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Colorado Breaches
Search all breaches reported in Colorado
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits