Perry Johnson Corruption & EthicsBillionaires & Big Business Michigan

Perry Johnson Says He'll Run Michigan Like His Businesses. One of Them Exposed 14 Million Patients' Medical Records.

The self-styled 'quality guru' wants Michigan voters to hire him because of how he runs his companies. One of them let hackers sit inside its network for five weeks, waited months to tell anyone, and became the biggest health care data breach of 2023.

Perry Johnson Says He'll Run Michigan Like His Businesses. One of Them Exposed 14 Million Patients' Medical Records.

Michigan Republicans pick a nominee for governor tomorrow, August 4. One of the men on that ballot has spent more than $30 million of his own money telling voters a single story about himself: that he is a businessman who knows how to make things work.

Perry Johnson calls himself the "quality guru." He put it plainly at a campaign stop in Grand Rapids: "I am the quality guru, and I intend to bring it to Michigan." His pitch is that the standards and audits he sold to auto suppliers for forty years can be pointed at state government. He told MLive he's "the perfect DOGE guy." Asked by Michigan Public to explain the sweeping efficiency audit at the center of his campaign, he said it's "basically the same thing that I do in every company" — and that where Gov. Whitmer won't audit anything, "I propose we audit everything."

Fine. Let's audit something.

The biggest health care data breach of the year

Perry Johnson & Associates is a medical transcription firm — the company hospitals hire to turn a doctor's dictated notes into a written record. It's part of the business empire that carries Johnson's name, and in a 2018 legal filing it boasted that it was the largest privately held transcription company in the country, with $43 million in revenue.

To do that work, hospitals hand the company their patients' most private information. Then, in the spring of 2023, someone took it.

An unauthorized party was inside PJ&A's network from March 27 to May 2, 2023 — more than a month — copying files before anyone noticed. The stolen files held names, addresses, dates of birth, medical record numbers, hospital account numbers, admission diagnoses, and the dates and times people were treated. For some patients they also held Social Security numbers, insurance information, and the actual clinical content of the transcription files: lab and diagnostic test results, medications, the name of the treatment facility, and the names of their doctors.

That's not a mailing list. That's a person's medical life.

The count kept climbing. PJ&A reported the breach to federal regulators as affecting 8,952,212 people. Then its clients started filing their own reports. When Concentra confirmed in January 2024 that 3,998,162 of its patients were caught up in it, the total passed 14 million — making it the largest health data breach reported to regulators in all of 2023.

Among the institutions whose patients were exposed:

  • Cook County Health in Chicago — 1.2 million patients of the public hospital system that serves some of the poorest people in Illinois
  • Northwell Health, New York's largest health system and private employer — a draft figure of 3,891,565 was later retracted, and no final count was ever confirmed
  • North Kansas City Hospital and its Meritas clinics — 502,438
  • Mercy Medical Center in Cedar Rapids, Iowa — 97,132
  • Crouse Health in Syracuse and Salem Regional Medical Center in Ohio — totals never disclosed

New York's attorney general was alarmed enough to issue a statewide consumer alert. On November 28, 2023, Letitia James warned roughly 4 million New Yorkers that their information was out there and urged them to protect themselves against identity theft.

Six months of silence

Here's the part that should bother a voter being asked to trust this man with a state government.

The company says it detected the intrusion on May 2, 2023. It did not tell the hospitals whose patients' data it was holding until July 21 — eighty days later. Its investigation didn't wrap up until September 28. Patients themselves didn't get letters in the mail until November — more than six months after the breach was detected, a delay that became one of the central allegations in the lawsuits that followed.

Federal law is not vague about this. Under HIPAA, a vendor holding patient data for a hospital must notify that hospital "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." Eighty days is not sixty days.

Every one of those days was a day a patient didn't know to freeze their credit, watch their accounts, or check their insurance statements for charges that weren't theirs.

And PJ&A's own breach notice, when it finally came, made no mention of offering credit monitoring or identity theft protection to the millions of people it had exposed. Some of its hospital clients ended up arranging that themselves.

Several of them didn't stop there. North Kansas City Hospital and Meritas severed all ties with the company. Mercy Medical Center stopped using its transcription services. Cook County Health ended the relationship too.

That is what customers do when they lose confidence in a vendor's quality.

A federal grand jury got involved

In November 2023, a federal grand jury started asking questions.

WBEZ Chicago — which had to sue Cook County Health under the Illinois open records law to get a copy — obtained a subpoena sent to the county health system on November 17, 2023. It came from the acting U.S. Attorney in Chicago and a prosecutor in the Justice Department's Fraud Section, and it demanded "any and all information related to the data security incident" involving PJ&A.

Specifically, prosecutors wanted:

  • PJ&A's contract with Cook County
  • records relating to "due diligence by Cook County of PJ&A"
  • every communication the county had with the company about the breach
  • a "list of affected individuals and corresponding data that was compromised"
  • any documents "related to identifying the unauthorized third party which accessed PJ&A data"

Cook County Health had ten days to hand it all to an FBI agent.

Be clear about what this does and does not mean: no charges have been reported against the company, and none against Perry Johnson personally. The subpoena went to a customer, not to him. But a Justice Department fraud unit demanding a company's contract and the due diligence records a client kept on it is not a routine hacking investigation into whoever broke in. Rachel Rose, a regulatory attorney not involved in the case, told BankInfoSecurity that three criminal statutes came to mind — the Stored Communications Act, criminal HIPAA violations, and identity theft. Given the facts, she said, "it is not surprising that the DOJ would pursue a potential criminal case."

Meanwhile the civil cases piled up — at least 40 of them by the end of January 2024, all alleging the company was negligent in failing to protect the data it was paid to hold. A federal judicial panel consolidated them into a single multidistrict litigation in the Eastern District of New York, with the 2023 breach of PJ&A's network at its core.

"Quality" has a track record

If this were a one-off, it would be bad luck. It isn't the first time a company with Johnson's name on it has had its quality questioned.

Bridge Michigan's 2022 investigation found that in the early 2000s, the U.S. Registrar Accreditation Board suspended Perry Johnson Registrars from issuing aerospace certifications after Boeing complained it had caught Johnson's companies violating conflict-of-interest rules twice in six months — one company teaching businesses how to pass audits, a sister company then conducting the audits. Board attorneys wrote at the time that the potential for "wink and nod" arrangements "was obvious."

"That's a big taboo," a quality-industry watchdog told Bridge. "You can't audit your own work, and you can't certify your own work."

The same reporting documented lawsuits over millions of junk faxes in the 1990s, and an agreement Johnson's company reportedly signed in 2004 to staff a telemarketing call center with Oregon state prisoners — news accounts at the time said it beat the cost of moving the work to India. Johnson's companies have denied institutional wrongdoing, and industry figures told Bridge the registrar firm's reputation has improved since he sold off the consulting arm.

But the man is not running on his companies' current org charts. He is running on the word quality, in an ad that told Michigan voters, "When your car door closes just right, thank Perry Johnson." He chose that standard. He should be measured against it.

What this has to do with Michigan

The state of Michigan holds an enormous amount of your data — tax records, unemployment claims, Medicaid files, driver's license information. Johnson has said his audit for state government would be "basically the same thing that I do in every company." And he wants to run it while eliminating the personal income tax, which MLive notes makes up nearly 30% of state revenue and brought in more than $13 billion in the 2024-25 fiscal year, covering the hole with efficiency savings he has not itemized.

Fourteen million people already found out what "run it like my business" can mean. They didn't get a vote. Michigan does.

Perry Johnson wants to run Michigan's government like his businesses. Millions of patients whose medical records were exposed know what that looks like. We deserve better.

Sources

Perry Johnson Report Card