SSM Health Care Corporation
ent_019e07c9688e9c3db3dfb77071ceeedf
Disclosures
6
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
29,579
nationwide · HHS OCR MO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SSM Health Care Corporation
- Normalized
- ssm health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493000QP6H63JFPC580
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ssmhealth.com
Disclosure history (6)newest first
- OKLAHOMAHHS OCRas victim2026-03-11
SSM Health (Oklahoma) reported to HHS OCR on 2026-03-11 a Hacking/IT Incident affecting 597 individuals. Breached information was located on a Network Server. A business associate was present. No further details were provided in the HHS web description.
- Indiana State AGas victim2023-09-20
SSM Health reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-20 and was reported on 2023-09-20. 9 Indiana residents were affected. 5,364 individuals affected in total.
- Massachusetts State AGas victim2017-12-29
SSM Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-29. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- MISSOURIHHS OCRas victim2017-12-28
SSM Health reported to HHS on 2017-12-28 a Unauthorized Access/Disclosure affecting 29579 individuals. Breached information located on Electronic Medical Record. A former employee used acquired PHI to fraudulently obtain prescriptions. The CE notified HHS, individuals, media, and law enforcement, provided identity theft protection, and implemented additional safeguards and staff retraining.
- MISSOURIHHS OCRas reporting2017-06-09
SSM Health (Dr. Sayed Khader, SSMH Medical Group, DePaul Hospital Clinic) reported to HHS on 2017-06-09 a Theft affecting 836 individuals. Between April 12–13, 2017, a component of an EMG medical device was stolen; it stored PHI including patients' names, dates of birth, chief complaints, and medical record numbers. Breached information located on an 'Other' portable medical device. CE updated policies, retrained staff, encrypted the device, and completed a system-wide Risk Analysis. OCR closed with documented voluntary corrective actions (May 2018).
- MISSOURIHHS OCRas victim2015-10-09
SSM Health Cancer Care reported to HHS on 2015-10-09 an Unauthorized Access/Disclosure affecting 670 individuals. Breached information located on Paper/Films. The covered entity erroneously mailed letters to the addresses of other patients due to using an inaccurate electronic file. The breach included individuals’ names and their inferred treatment relationship.