ST. JOSEPH HEALTH SYSTEM
ent_019e0b1f9948413e7f3dcf945cbe6a83
Disclosures
9
HHS OCR · HHS OCR enforcement · State AG · 6 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
405,000
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ST. JOSEPH HEALTH SYSTEM
- Normalized
- st joseph health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 2O0NF2YLF8UP2CQEIS20
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- stjosephhealth.org
Disclosure history (9)newest first
- INDIANAHHS OCRas reporting2020-05-28
Saint Joseph Regional Medical Center, Inc. reported to HHS on 2020-05-28 a Improper Disposal affecting 1000 individuals. Breached information located on Paper/Films. A business associate improperly discarded documents containing PHI (names, SSNs, diagnoses, financial info). The CE notified HHS, individuals, media, and law enforcement, and destroyed the records.
- FEDERALHHS OCR enforcementas victim2016-10-17
St. Joseph Health agreed to a $2,140,500 HIPAA settlement for making PHI publicly accessible via internet search engines from 2011 to 2012.
- TEXASHHS OCRas victim2014-03-05
St. Joseph Health System reported to HHS on 2014-03-05 a Hacking/IT Incident affecting 3300 individuals. Breached information located on Network Server. Business associate present.
- California State AGas victim2014-03-03
St. Joseph Health disclosed an inadvertent email misdelivery on February 18, 2014, where an employee sent a Microsoft Excel file containing patient information (names, patient codes, referral/admission details) to an employee at Cain Brothers, an investment firm. The file was not encrypted. St. Joseph Health discovered the error the same evening, contacted the recipient, and confirmed the file was deleted. No SSNs or financial data were included. The organization retrained staff and reviewed policies.
- Massachusetts State AGas victim2014-02-11
St. Joseph Health System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-02-11. 63 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2014-02-05
St. Joseph Health System experienced a security attack between December 16 and 18, 2013, where hackers gained unauthorized access to one server. The incident potentially affected patients, employees, and beneficiaries, exposing names and possibly addresses. SJHS shut down the server, engaged forensic experts, and is cooperating with the FBI. Identity protection services were offered.
- TEXASHHS OCRas victim2014-02-05
St Joseph Health System reported to HHS on 2014-02-05 a Hacking/IT Incident affecting 405,000 individuals. Breached information located on Network Server. The server was hacked during a power surge, exposing ePHI including names, DOB, SSN, medical info, bank account info, and addresses. The CE provided breach notification to HHS, affected individuals, and the media, and improved administrative and technical security.
- New Hampshire State AGas victim2014-02-03
St. Joseph Health System notified NH AG of a security attack between Dec 16-18, 2013, discovered Dec 18. Hackers from China accessed a server potentially compromising PHI, SSNs, and financial data of 17 NH residents. Investigation ongoing; no confirmation data was taken. FBI notified, credit monitoring offered.
- CALIFORNIAHHS OCRas victim2012-02-15
St. Joseph Health System (CA) reported to HHS OCR on 2012-02-15 an Unauthorized Access/Disclosure affecting 12,234 individuals (HHS portal count; OCR investigation found 31,800 individuals actually exposed). ePHI stored on a network server was publicly accessible via internet search engines (e.g. Google) from Feb 1, 2011 to Feb 13, 2012, due to default file-sharing application settings left unconfigured. Data exposed included patient names, health statuses, diagnoses, and demographics. SJH settled with OCR for $2,140,500 and agreed to a corrective action plan.