BAYSTATE HEALTH, INC.
bd_9ff206fc833165c3 · schema v1 · pii pii-v1
Full breach record for BAYSTATE HEALTH, INC. →Baystate Health, Inc. reported to HHS on October 21, 2016, a hacking incident that affected 13,112 individuals. The breach occurred on July 27, 2016, when five employees responded to a phishing email, allowing hackers to access their email accounts. The compromised information, located in the email accounts, potentially included patient names, demographic information, dates of birth, diagnoses, treatments, medical record numbers, and health insurance ID numbers. In response, the company retrained employees, issued phishing reminders, and improved technical safeguards.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 21, 2016
- Raw hash
- 74b1d050c693a891791bb04b00919015150725aafcda62d976d0d5b765dd2d9a
Source filing
Reporting entity
- Name
- BAYSTATE HEALTH, INC.norm: baystate health
- Industry
- Health Care Services
Victim entity
- Name
- BAYSTATE HEALTH, INC.norm: baystate health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 13,112
- Data types
- HEALTH_BASICIDENTITY_BASICPHIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Regulator citations
- Notified HHSOCR reviewed HIPAA policies and proceduresObtained assurances of corrective action from OCR
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.