Saint Louis University
ent_019e0a5f8726c5f2c13ed3bdded6ce89
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
93,612
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Saint Louis University
- Normalized
- saint louis university— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300Z565MB9CYIFO02
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- slu.edu
Disclosure history (5)newest first
- Maine State AGas victim2024-03-15
Saint Louis University, an educational institution, reported a data breach impacting 93,612 individuals. The incident, described as an external system breach or hacking, occurred between December 23, 2022, and July 26, 2023, and was discovered on April 24, 2023. The compromised information included names and Social Security numbers. The university began notifying affected individuals on March 15, 2024, and offered 12 months of identity protection services through Experian.
- Indiana State AGas victim2024-03-15
Saint Louis University reported a data breach to the Indiana Attorney General. The breach occurred on 2022-12-23 and was reported on 2024-03-15. 1 Indiana residents were affected. 93,612 individuals affected in total.
- Montana State AGas victim2023-10-19
Saint Louis University notified Montana residents of a data breach involving unauthorized access to email accounts containing personal information. The incident was discovered on March 2, 2023, following suspicious activity. Forensic investigators confirmed access to specific accounts and limited documents on SharePoint/OneDrive. Affected data likely included names and other PII. No evidence of fraud was found at the time of notification.
- MISSOURIHHS OCRas victim2023-05-01
Saint Louis University reported to HHS on 2023-05-01 a Hacking/IT Incident affecting 48,392 individuals. Breached information located on Email. The incident involved an email phishing scheme targeting employees, exposing PHI (names, addresses, DOB, driver's license, SSN, claims, financial info, diagnoses, lab results, medications). The entity notified HHS, individuals, and media, and implemented additional safeguards and staff retraining.
- MISSOURIHHS OCRas victim2011-02-10
Saint Louis University (MO), a Healthcare Provider, reported to HHS on 2011-02-10 a Hacking/IT Incident (cyber-attack) affecting the ePHI of approximately 800 individuals. Breached information was located on a Desktop Computer. The ePHI involved included names, diagnoses, and clinical and treatment information. The CE notified HHS, affected individuals, and the media, and implemented enhanced administrative, technical, and security safeguards, including monthly security awareness training. OCR provided technical assistance regarding the HIPAA Security Rule.