INOVA HEALTH SYSTEM FOUNDATION
ent_019e0a5ddeb9f5f553f85186bb633b45
Disclosures
7
HHS OCR · State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,045,270
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INOVA HEALTH SYSTEM FOUNDATION
- Normalized
- inova health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001L7PBVS286Y307
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- VAHHS OCRas victim2021-01-22
Inova Health System reported to HHS on 2021-01-22 a Unauthorized Access/Disclosure affecting 1680 individuals. Breached information located on Email. An employee inadvertently emailed PHI (names, DOB, diagnoses, medications) to the wrong recipient. The CE notified HHS, affected individuals, and the media, established a call center, sanctioned the employee, and retrained staff.
- 🦫Oregon State AGas victim2020-09-22
Inova Health System reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-22. The breach occurred during 2/7/2020 - 5/20/2020. The breach was discovered on 7/16/20208/10/2020. 1,045,270 individuals were affected. Notice was sent on 9/9/2020.
- 🐻California State AGas victim2020-09-15
Inova Health System reported a data security incident involving third-party provider Blackbaud. A ransomware attack occurred between February 7, 2020, and May 20, 2020. The threat actor exfiltrated patient and donor information, including names, addresses, dates of birth, phone numbers, provider names, dates of service, and philanthropic giving history. Inova engaged cybersecurity professionals and set up a response line. Blackbaud paid the threat actor to destroy the data.
- VAHHS OCRas victim2020-09-09
Inova Health System (VA, Healthcare Provider) reported to HHS OCR on 2020-09-09 that its business associate experienced a ransomware attack on a network server affecting the ePHI of approximately 1,045,270 individuals. Exposed data included names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice.
- 🌲Washington State AGas victim2020-09-09
Inova Health System, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2020-08-10 and filed notice on 2020-09-09. 2,470 Washington residents were affected. 30 days elapsed between awareness and notification. 185 days to identify the breach. 0 days to contain the breach.
- VAHHS OCRas victim2018-11-19
Inova Health System reported to HHS on 2018-11-19 a Hacking/IT Incident affecting 13,596 individuals. Breached information located on Electronic Medical Record. The covered entity was Valley Health System. The BA implemented additional administrative, technical, and security safeguards to better protect PHI, and retrained its staff.
- 🦬Montana State AGas victim2018-11-02
Inova Health System (Inova) reported a data breach to the Montana Attorney General. The breach was reported on 2018-11-02. The breach occurred from 1/1/2017 to 10/31/2017. 3 Montana residents were affected.