MedStar St. Mary's Hospital
bd_03b72af862dd9d81 · schema v1 · pii pii-v1
Full breach record for MedStar St. Mary's Hospital →MedStar St. Mary's Hospital (MD) reported to HHS OCR that its business associate experienced a cybersecurity attack affecting PHI of 172,915 individuals. Compromised data included names, addresses, dates of birth, driver's license numbers, Social Security numbers, diagnoses/conditions, lab results, medications, and health insurance information. The breach was reported on 2025-05-29 and involved a network server. Response included HHS, individual, and media notifications, substitute notice, complimentary credit monitoring, and implementation of additional safeguards. The specific business associate is not named in the OCR portal entry.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 29, 2025
- Raw hash
- da5f0e09d611168738d4b97787542269766ff587ff0a4d7a420af8f829cf60bf
Source filing
Reporting entity
- Name
- MedStar St. Mary's Hospitalnorm: medstar st mary s hospital
- Industry
- Healthcare Provider
Victim entity
- Name
- MedStar St. Mary's Hospitalnorm: medstar st mary s hospital
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 172,915
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- HHS OCR breach report filed
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.