CMS notifies 1 million of data breach
The Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS) have begun notifying individuals of a...
3 min read
Kirsten Peremore
Aug 28, 2025 5:30:00 AM
On January 13, 2025, Fundamental Administrative Services, LLC, a healthcare management services company based in Sparks, Maryland, detected suspicious network activity within its systems that support more than 85 skilled nursing facilities and rehabilitation centers across Indiana, Maryland, Nevada, New Mexico, South Carolina, Texas, and Wisconsin.
A forensic investigation revealed that the company’s network had been subject to unauthorized access for approximately two and a half months, from October 27, 2024, through January 13, 2025, during which files containing HIPAA-protected data were exfiltrated. The review of compromised files confirmed exposure of sensitive information belonging to 56,235 individuals.
Fundamental Administrative Services initially reported the incident to the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) with a placeholder figure of 500 affected individuals, but later updated the report once the scope was confirmed. The company has since taken action to secure its systems, launched a comprehensive review of its policies, procedures, and data access practices, and notified the 87 affected skilled nursing and rehabilitation facilities.
According to DataBreaches.net the organizations affected include:
The Databreaches.net post on the breach notes, “Fundamental first became aware of suspicious activity on its network on January 20, 2025. Their investigation revealed that there was unauthorized access between October 27, 2024 and January 13, 2025. They offer no explanation for why it was not detected in October or earlier than months later.”
See also: HIPAA Compliant Email: The Definitive Guide (2025 Update)
A business associate is a person or entity that performs functions or services for a HIPAA-covered entity (like a hospital, nursing home, or insurer) that involve the use or disclosure of protected health information (PHI).
Covered entities are healthcare providers, health plans, and healthcare clearinghouses that directly collect or manage PHI. Business associates, on the other hand, support covered entities by providing services such as billing, IT support and claims processing.
Yes. The HHS Office for Civil Rights (OCR) can impose civil monetary penalties directly on Business Associates if they fail to safeguard PHI or do not comply with HIPAA rules.
The Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS) have begun notifying individuals of a...
In July 2024, a cybersecurity incident occurred involving Nationwide Recovery Services (NRS), a debt collection agency based in Cleveland, Tennessee,...
The Wisconsin ambulance service provider has notified the Department of Health and Human Services of a data breach impacting approximately 114,000...