Advocate Health Care Network
ent_019e0a5a17f455a2aa0bd23507e0241b
Disclosures
7
HHS OCR enforcement · HHS OCR · State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,029,530
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Advocate Health Care Network
- Normalized
- advocate health care network— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900DS38JBG7894Y26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- FEDERALHHS OCR enforcementas victim2016-08-04
Advocate Health Care Network settled potential HIPAA violations involving ePHI for $5.55 million and adopted a corrective action plan.
- ILLINOISHHS OCRas reporting2013-09-13
Advocate Health and Hospitals Corporation d/b/a Advocate Medical Group reported to HHS on 2013-09-13 a Hacking/IT Incident affecting 2029 individuals. Breached information located on Network Server. The entity is a Business Associate. The breach involved ePHI including demographic, clinical, insurance, and financial data. A $5.55 million settlement was reached with OCR.
- Massachusetts State AGas reporting2013-08-26
Advocate Medical Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-08-26. 1,437 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2013-08-23
Advocate Medical Group notified the NH AG that an administrative office in Park Ridge, IL was burglarized on July 14-15, 2013. Four password-protected but unencrypted computers containing patient demographic, SSN, and limited clinical data were stolen. AMG notified 271 NH residents on August 23, 2013, offering one year of credit monitoring.
- California State AGas reporting2013-08-23
Advocate Medical Group reported a data breach to the California Attorney General. The incident occurred on July 15, 2013. The notification was filed on August 23, 2013. The breach involved protected health information (PHI) and personally identifiable information (PII), including names, addresses, and potentially Social Security numbers. The specific attack vector and number of affected individuals are not detailed in the provided summary fields.
- ILLINOISHHS OCRas reporting2013-08-23
Advocate Health and Hospitals Corporation, d/b/a Advocate Medical Group reported to HHS on 2013-08-23 a theft affecting 4,029,530 individuals. The investigation revealed multiple security failures, including the theft of an unencrypted laptop from a vehicle. Breached data included patient names, addresses, dates of birth, credit card numbers, and clinical and health insurance information. The breached information was located on a desktop computer.
- ILLINOISHHS OCRas victim2010-01-22
Advocate Health Care (IL) reported to HHS OCR on 2010-01-22 a Theft affecting 812 individuals. On November 24, 2009, an Advocate nurse's laptop was stolen, containing PHI including names, addresses, dates of birth, Social Security numbers, insurance information, medications, and diagnoses. Breached information was located on a Laptop. No business associate was involved. Following the breach, Advocate revised mobile device security policies and OCR required workforce mobile-device users to submit acknowledgment forms.