The Children's Mercy Hospital
ent_019e0b0ac84a917d2c72c772de4e6bc4
Disclosures
5
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
65,930
as filed · HHS OCR MO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Children's Mercy Hospital
- Normalized
- the children s mercy hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300CD9UCEUKMTTN26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- FEDERALHHS OCRas victim2018-06-27
Children's Mercy Hospital reported to HHS on 2018-06-27 a Hacking/IT Incident affecting 1463 individuals. A hacker used a software-defined radio (SDR) or similar device to intercept protected health information (PHI) transmitted via the hospital's pager system, including names, diagnoses, and treatment information.
- 🦬Montana State AGas victim2018-04-30
Children's Mercy Hospital reported a data breach to the Montana Attorney General. The breach was reported on 2018-04-30. The breach occurred from 12/2/2017 to 1/4/2018. 3 Montana residents were affected.
- MOHHS OCRas victim2018-01-31
Children's Mercy Hospital (MO) reported to HHS on 2018-01-31 a Hacking/IT Incident (email phishing attack) affecting 65,930 individuals. Multiple employees were victims of a phishing attack that compromised PHI including names, addresses, dates of birth, diagnoses, lab results, and other treatment information. Breached information was located in Email. In response, the CE retrained employees on email security and implemented additional technical safeguards. No business associate was involved.
- 🦬Montana State AGas victim2017-05-19
Children's Mercy Hospital reported a data breach to the Montana Attorney General. The breach was reported on 2017-05-19. The breach occurred from 3/23/2016 to 3/27/2017. 1 Montana residents were affected.
- FEDERALHHS OCRas victim2017-05-19
Children's Mercy Hospital reported to HHS on 2017-05-19 an unauthorized access/disclosure incident affecting 5,511 individuals. A physician stored protected health information, including names, dates of birth, and medical diagnoses, on a personal website. In response, the hospital updated policies, retrained employees, and sanctioned the physician.