The Children's Mercy Hospital
ent_019e0b0ac84a917d2c72c772de4e6bc4
Disclosures
8
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
65,930
nationwide · HHS OCR MO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Children's Mercy Hospital
- Normalized
- the children s mercy hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300CD9UCEUKMTTN26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- MISSOURIHHS OCRas victim2018-06-27
Children's Mercy Hospital reported to HHS on 2018-06-27 a Hacking/IT Incident affecting 1463 individuals. A hacker used a software-defined radio (SDR) or similar device to intercept protected health information (PHI) transmitted via the hospital's pager system, including names, diagnoses, and treatment information.
- New Hampshire State AGas victim2018-04-30
Children's Mercy Hospital notified the NH Attorney General of a phishing attack compromising five employee email accounts between Dec 2017 and Jan 2018. Unauthorized parties downloaded mailbox contents, exposing PHI (medical records, diagnoses) and PII for 2 NH residents. Accounts were reset upon detection. The hospital engaged forensic experts, retrained staff on phishing, and offered 12 months of identity protection to affected individuals.
- Montana State AGas reporting2018-04-30
Children's Mercy Kansas City notified patients and staff of a phishing incident affecting five employee email accounts between Dec 2017 and Jan 2018. Unauthorized access led to the download of mailbox contents, exposing PHI and PII (names, MRNs, DOB, etc.) of potentially affected patients. The company reset accounts, engaged forensic experts, and provided 12 months of identity protection.
- Massachusetts State AGas victim2018-04-30
Children's Mercy Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-30. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- MISSOURIHHS OCRas victim2018-01-31
Children's Mercy Hospital (MO) reported to HHS on 2018-01-31 a Hacking/IT Incident (email phishing attack) affecting 65,930 individuals. Multiple employees were victims of a phishing attack that compromised PHI including names, addresses, dates of birth, diagnoses, lab results, and other treatment information. Breached information was located in Email. In response, the CE retrained employees on email security and implemented additional technical safeguards. No business associate was involved.
- Montana State AGas reporting2017-05-19
Children's Mercy Kansas City notified patients that an unauthorized website containing patient information was discovered on March 23, 2017. A physician had uploaded data to create an educational resource. The website lacked adequate security controls. Data included names, MRNs, DOBs, and clinical codes. No SSNs or financial data were involved. Identity protection services were offered.
- MISSOURIHHS OCRas victim2017-05-19
Children's Mercy Hospital reported to HHS on 2017-05-19 an unauthorized access/disclosure incident affecting 5,511 individuals. A physician stored protected health information, including names, dates of birth, and medical diagnoses, on a personal website. In response, the hospital updated policies, retrained employees, and sanctioned the physician.
- MISSOURIHHS OCRas victim2014-08-15
Children's Mercy Hospital reported to HHS on 2014-08-15 a Hacking/IT Incident affecting 4067 individuals. Breached information located on Network Server. The business associate StayWell Health Management and subcontractor Onsite Health Diagnostics were involved. PHI including names, contact info, and encrypted passwords was accessed.