OPKO Health, Inc. - Form 8-K Summary
Business Context and Reporting Period
This Form 8-K was filed by OPKO Health, Inc. on June 3, 2019, regarding a data security incident involving its subsidiary, BioReference Laboratories, Inc. The report addresses unauthorized activity discovered on the web payment page of an external collection agency, Retrieval-Masters Creditors Bureau, Inc. d/b/a American Medical Collection Agency ("AMCA").
Key Financial Metrics
The filing text does not provide specific values for revenue, profit, cash flow, margins, debt, or liquidity. This report focuses exclusively on a regulatory disclosure regarding a cybersecurity incident and does not contain financial performance data.
Material Changes and Incident Details
- Incident Timeline: Unauthorized activity occurred between August 1, 2018, and March 30, 2019.
- Scope of Data: Approximately 422,600 patients for whom BioReference performed testing were potentially affected.
- Data Compromised: Patient name, date of birth, address, phone, date of service, provider, balance information, credit card information, bank account information, and email addresses.
- Data Not Compromised: No Social Security Numbers, passwords, security questions, laboratory results, or diagnostic information were compromised.
- Direct Impact: Notices are being sent to approximately 6,600 patients whose credit card or bank account information was stored in the affected system.
Management Commentary, Risks, and Contingencies
BioReference has not been able to verify the accuracy of the information received from AMCA. The company has ceased sending collection requests to AMCA since October 2018 and has requested that AMCA stop working on any pending collection requests involving BioReference patients. AMCA is providing identity protection and credit monitoring services for 24 months to affected patients and has reported the incident to law enforcement. BioReference plans to take additional steps once more information is obtained.
Key Facts for Investor Verification
- Verify the final count of affected patients and the specific nature of the data breach as confirmed by independent investigation.
- Monitor for potential legal liabilities, regulatory fines, or class-action lawsuits arising from the incident.
- Assess the financial impact of the 24-month identity protection services provided to approximately 6,600 patients.
- Review the company's vendor risk management protocols following the cessation of business with AMCA.