INOVA HEALTH SYSTEM FOUNDATION
ent_019e0a5ddeb9f5f553f85186bb633b45
Disclosures
13
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,045,270
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INOVA HEALTH SYSTEM FOUNDATION
- Normalized
- inova health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001L7PBVS286Y307
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- New Hampshire State AGas victim2023-02-27
Inova Health System Foundation notified NH AG of unauthorized access to an employee computer on Oct 21, 2022. One NH resident's name and SSN were at risk. Inova investigated, deleted data, and offered 1-year credit monitoring.
- VIRGINIAHHS OCRas victim2021-01-22
Inova Health System reported to HHS on 2021-01-22 a Unauthorized Access/Disclosure affecting 1680 individuals. Breached information located on Email. An employee inadvertently emailed PHI (names, DOB, diagnoses, medications) to the wrong recipient. The CE notified HHS, affected individuals, and the media, established a call center, sanctioned the employee, and retrained staff.
- Oregon State AGas victim2020-09-22
Inova Health System reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-22. The breach occurred during 2/7/2020 - 5/20/2020. The breach was discovered on 7/16/20208/10/2020. 1,045,270 individuals were affected. Notice was sent on 9/9/2020.
- California State AGas victim2020-09-15
Inova Health System notified patients of a data security incident involving third-party provider Blackbaud. A ransomware attack on Blackbaud between Feb 7 and May 20, 2020, resulted in data exfiltration. Inova was notified on July 16, 2020. Affected data includes names, addresses, DOBs, phone numbers, provider names, dates of service, hospital departments, and philanthropic giving history. SSNs and financial account info were not exposed. Blackbaud paid the ransom to ensure data destruction.
- VIRGINIAHHS OCRas victim2020-09-09
Inova Health System (VA, Healthcare Provider) reported to HHS OCR on 2020-09-09 that its business associate experienced a ransomware attack on a network server affecting the ePHI of approximately 1,045,270 individuals. Exposed data included names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice.
- Washington State AGas victim2020-09-09
Inova Health System notified Washington AG of a third-party ransomware attack on Blackbaud (Feb-May 2020). Inova determined on Aug 10, 2020 that patient/donor PII (names, DOB, contact info, giving history) was accessed. 2,470 WA residents affected. Ransom paid by Blackbaud for data destruction. Inova engaged forensic experts and notified residents.
- Illinois State AGas victim2020-01-01
INOVA HEALTH SYSTEM filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-362). The register records the breach as discovered on February 7, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- VIRGINIAHHS OCRas victim2018-11-19
Inova Health System reported to HHS on 2018-11-19 a Hacking/IT Incident affecting 13,596 individuals. Breached information located on Electronic Medical Record. The covered entity was Valley Health System. The BA implemented additional administrative, technical, and security safeguards to better protect PHI, and retrained its staff.
- New Hampshire State AGas victim2018-11-05
Inova Health System notified NH AG that unauthorized access to patient records occurred between Jan-Oct 2017 via stolen employee credentials. 10 NH residents affected (names, DOB, SSN, MRNs). Discovered Sept 5, 2018. Notifications mailed Nov 2, 2018 with 1-year credit monitoring.
- VIRGINIAHHS OCRas victim2018-11-02
Inova Health System reported to HHS on 2018-11-02 a Hacking/IT Incident affecting 13,596 individuals. Breached information located on Electronic Medical Record, Paper/Films. The incident involved a cyber-attack on the business associate, resulting in the exfiltration of PHI including names, addresses, DOBs, SSNs, and medical record numbers.
- Montana State AGas victim2018-11-02
Inova Health System notified Montana residents of a breach where an unauthorized individual used stolen employee credentials to access patient billing records between Jan-Oct 2017. Data exposed included names, addresses, DOBs, MRNs, and SSNs. Inova engaged forensic investigators and law enforcement (HSI) and offered 1 year of credit monitoring.
- Massachusetts State AGas victim2013-03-08
Inova Health System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-03-08. 22 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2013-03-07
Inova Health System notified the NH AG that a misconfigured Lawson eProfile application folder containing employee W-2 forms (SSN, name, address, earnings) was accessible to the internet. Discovered Feb 8, 2013. 4 NH residents affected. Notifications sent March 8, 2013. Credit monitoring offered.
Supply-chain cascadesreviewed and confirmed
- INOVA HEALTH SYSTEM FOUNDATION’s filing is one of at least 175 in the BLACKBAUD, INC. supply-chain incident (2020).