Reid and Riege, P.C. Data Breach
Reid and Riege Law Firm Network Server Breach Affects 610
What happened in the Reid and Riege, P.C. data breach?
The Reid and Riege, P.C. data breach was reported on September 28, 2022 and affected 610 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Connecticut. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Reid and Riege, P.C. Breach Details
Reid and Riege, P.C., a Connecticut-based law firm, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the Connecticut Attorney General on September 28, 2022, affecting 610 individuals whose protected health information (PHI) and other sensitive personal data were stored on the compromised network systems. As a business associate to healthcare entities, the firm's breach represents a violation of HIPAA Business Associate Agreement (BAA) obligations and triggered mandatory notification requirements under the Health Insurance Portability and Accountability Act.
Company Response
Upon discovery of the unauthorized access to their network server, Reid and Riege, P.C. initiated an investigation to determine the scope and nature of the breach. The firm worked to identify all affected individuals and the specific data elements that may have been accessed or exfiltrated by unauthorized actors. The organization notified affected parties in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured PHI. The firm also notified the Connecticut Attorney General and likely engaged with their business associate partners to coordinate breach response efforts.
Specific Details
The breach occurred on the firm's network server infrastructure, which typically indicates a compromise of centralized data storage systems rather than an isolated endpoint or portable device. Network server breaches of this nature commonly result from vulnerabilities such as unpatched software, weak authentication credentials, exposed remote access points (RDP, VPN), or successful phishing campaigns targeting employee credentials. The fact that this incident is classified as a "hacking/IT incident" suggests active exploitation by threat actors rather than accidental loss or theft. Network-based breaches often result in broader data exposure because servers typically contain consolidated records from multiple clients and time periods. The attackers may have maintained access for an extended period before detection, potentially allowing them to exfiltrate large volumes of data or move laterally through connected systems.
Organizational Context
Reid and Riege, P.C. is a law firm operating in Connecticut that serves as a business associate to healthcare organizations. Law firms functioning as business associates typically handle healthcare-related legal matters, billing disputes, compliance issues, or represent healthcare providers in litigation. As a business associate, the firm is contractually obligated to maintain HIPAA compliance and implement appropriate administrative, physical, and technical safeguards to protect PHI. The firm's role as a business associate means it processes, stores, or transmits PHI on behalf of covered entities (such as hospitals, clinics, or health plans), making it subject to the same HIPAA requirements as covered entities themselves. The breach of a business associate's systems represents a significant compliance failure and indicates potential gaps in the firm's security infrastructure, employee training, or incident response capabilities.
Number of People Affected
The breach impacted 610 individuals whose information was stored on Reid and Riege's network servers. This population likely includes patients of healthcare providers represented by the firm, individuals involved in healthcare-related legal matters, and potentially employees or contractors with access to the firm's systems. The 610 affected individuals represent a moderate-scale breach in terms of raw numbers but carries significant implications given the sensitivity of healthcare information and the legal context in which it was stored.
Personal Information Involved
While the specific data elements exposed are not detailed in the breach submission, individuals affected by a law firm network server compromise may have had the following information exposed:
- Protected Health Information (PHI): Medical diagnoses, treatment records, medication information, and healthcare provider notes
- Personal Identifiers: Full names, dates of birth, and Social Security numbers
- Contact Information: Home addresses, telephone numbers, and email addresses
- Financial Information: Insurance policy numbers, billing account numbers, and payment information
- Legal Documentation: Case files, correspondence, and legal strategy documents containing sensitive health information
- Employment Records: If the firm employed healthcare workers or contractors, employment and credential information
The exposure of this combination of data types creates significant risk for identity theft, medical fraud, and privacy violations.
Likely Risks to Patients
Individuals affected by this breach face multiple categories of risk:
Identity Theft and Financial Fraud: Exposure of Social Security numbers, dates of birth, and financial account information creates substantial risk for identity theft. Threat actors can use this information to open fraudulent accounts, apply for credit, or conduct financial transactions in victims' names.
Medical Identity Theft: Criminals may use exposed healthcare information to obtain medical services, prescription medications, or medical equipment under victims' identities, potentially resulting in fraudulent medical bills and contaminated medical records.
Privacy Violations: The exposure of sensitive health information and legal documentation represents a fundamental violation of privacy expectations. Individuals may experience emotional distress and loss of privacy regarding sensitive health conditions or legal matters.
Insurance and Employment Discrimination: If health information becomes public, individuals may face discrimination from insurers, employers, or other entities that access the compromised data.
Targeted Attacks: Threat actors may use exposed information to conduct targeted phishing, social engineering, or other attacks against affected individuals or their healthcare providers.
Regulatory and Compliance Consequences: The breach may trigger additional regulatory investigations and potential penalties against both Reid and Riege, P.C. and their healthcare provider clients.
Recommended Actions for Patients
- Monitor Credit Reports: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
- Implement Identity Theft Monitoring: Enroll in credit monitoring and identity theft protection services, which may be offered by Reid and Riege, P.C. as part of their breach response. Monitor accounts for suspicious activity and consider using identity theft protection services for 2-3 years following the breach.
- Review Medical Records and Billing Statements: Request copies of medical records from healthcare providers to verify accuracy and check for signs of medical identity theft. Review explanation of benefits (EOB) statements and medical bills for unauthorized services or charges.
- Change Passwords and Enable Multi-Factor Authentication: Update passwords for healthcare portals, insurance accounts, and financial accounts. Enable multi-factor authentication wherever available to prevent unauthorized access even if credentials are compromised.
- Report Suspicious Activity: If you discover fraudulent accounts, unauthorized charges, or suspicious medical services, report them immediately to the relevant financial institutions, healthcare providers, and the Federal Trade Commission (FTC) at identitytheft.gov.
Industry Context
Network server breaches represent one of the most common vectors for healthcare data breaches, accounting for a significant percentage of HIPAA-reportable incidents annually. The involvement of a business associate in this breach highlights ongoing challenges in the healthcare ecosystem regarding third-party security. Business associates, including law firms, accounting firms, and IT service providers, have been the source of numerous large-scale healthcare breaches in recent years. The HIPAA Breach Notification Rule requires covered entities and business associates to implement reasonable and appropriate safeguards, conduct regular risk assessments, and maintain incident response plans. However, many organizations continue to experience breaches due to inadequate security controls, insufficient employee training, delayed patch management, and weak access controls. The September 2022 timeframe of this breach submission coincides with a period of increased ransomware and data exfiltration attacks targeting healthcare organizations and their business associates. Similar network server breaches affecting business associates have resulted in regulatory penalties, mandatory security improvements, and civil litigation from affected individuals.
Notification and Regulatory Requirements
Under the HIPAA Breach Notification Rule, Reid and Riege, P.C. was required to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The firm was also required to notify the Connecticut Attorney General and, if the breach affected more than 500 Connecticut residents, to notify prominent media outlets. The submission date of September 28, 2022 indicates the firm met its regulatory notification obligations by this date. Covered entities that received services from Reid and Riege, P.C. were also required to be notified so they could fulfill their own notification obligations to patients.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Reid and Riege, P.C. Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Enroll in credit monitoring and identity theft protection services, review accounts for suspicious activity, and monitor for signs of medical identity theft for 2-3 years following the breach
Request copies of medical records from healthcare providers to verify accuracy, review explanation of benefits statements and medical bills for unauthorized services, and report any suspicious medical charges immediately
Change passwords for healthcare portals, insurance accounts, and financial accounts; enable multi-factor authentication wherever available; and report any fraudulent accounts or unauthorized charges to financial institutions, healthcare providers, and the FTC at identitytheft.gov
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Connecticut Breaches
Search all breaches reported in Connecticut