Metro Presort
| Primary URL | Location | Industry | www[.]metropresort[.]com |
Country
United States of America
|
Healthcare
|
|---|
Profile
Metro Presort, also known by its alias, is a business associate that provides mail presorting and data processing services, primarily to healthcare organizations in the United States. Its headquarters are located in the United States of America, placing it within a national market for outsourced mail handling. The company’s core function involves sorting, bundling, and preparing large volumes of mail for delivery, a process that often includes handling documents containing protected health information. As a business associate under HIPAA, Metro Presort is required to implement safeguards for the confidentiality, integrity, and availability of any health data it processes.
The organization’s specialization in healthcare‑related mail distinguishes it from general presort vendors, aligning its operations with the specific compliance needs of medical providers, insurers, and pharmacies. In May 2019, Metro Presort was targeted by a ransomware attack that used the Ryuk strain, which encrypted its systems and initially led to the conclusion that no protected health information had been compromised because of pre‑existing encryption. Following a reinvestigation triggered by regulatory scrutiny, doubts emerged about the effectiveness of that encryption, and a later determination concluded that the personal health data of up to 38,387 individuals may have been exposed. The incident was first reflected on the U.S. Department of Health and Human Services breach reporting tool approximately 21 months after the attack, drawing attention to delayed disclosure patterns.
Separately, two of Metro Presort’s healthcare clients reported breaches affecting a combined total of over 24,000 patients, although the exact relationship between those figures and the business associate’s official breach count remains unclear. Regulatory investigators originally found no HIPAA violations but later acknowledged the potential for data compromise, illustrating the evolving assessment of the incident. The ransomware event is noted in industry reports as one of the Ryuk‑linked attacks that impacted 21 healthcare entities during 2019, underscoring its broader sector relevance. Information regarding Metro Presort’s ownership, parent company, or subsidiary structure is not provided in the available source material. Consequently, the profile focuses on the confirmed aspects of its services, market focus, and the notable security incident that has shaped its regulatory profile.
