ST. JOSEPH HEALTH SYSTEM
ent_019e0b1f9948413e7f3dcf945cbe6a83
Disclosures
5
HHS OCR · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
405,000
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ST. JOSEPH HEALTH SYSTEM
- Normalized
- st joseph health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 2O0NF2YLF8UP2CQEIS20
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- stjosephhealth.org
Disclosure history (5)newest first
- INDIANAHHS OCRas victim2020-05-28
Saint Joseph Regional Medical Center, Inc. reported to HHS on 2020-05-28 a Improper Disposal affecting 1000 individuals. Breached information located on Paper/Films. A business associate improperly discarded documents containing PHI (names, SSNs, diagnoses, financial info). The CE notified HHS, individuals, media, and law enforcement, and destroyed the records.
- 🐻California State AGas victim2014-03-03
St. Joseph Health (California) disclosed an error-based breach on February 18, 2014, where an employee inadvertently emailed an unencrypted Excel file containing patient names and health service details to an external investment firm (Cain Brothers). The breach was contained the same day upon recipient deletion. No SSNs or financial data were exposed. St. Joseph Health retrained staff and engaged Kroll for risk mitigation.
- 🐻California State AGas victim2014-02-05
St. Joseph Health System notified California AG in 2014 regarding a December 2013 security attack where hackers gained unauthorized access to a server. The breach potentially exposed patient and employee names and addresses. The system was shut down on Dec 18, 2013. Forensic experts and the FBI were engaged. No misuse of information was reported. Identity protection services were offered.
- TEXASHHS OCRas victim2014-02-05
St Joseph Health System reported to HHS on 2014-02-05 a Hacking/IT Incident affecting 405,000 individuals. Breached information located on Network Server. The server was hacked during a power surge, exposing ePHI including names, DOB, SSN, medical info, bank account info, and addresses. The CE provided breach notification to HHS, affected individuals, and the media, and improved administrative and technical security.
- FEDERALHHS OCRas victim2012-02-15
St. Joseph Health System (CA) reported to HHS OCR on 2012-02-15 an Unauthorized Access/Disclosure affecting 12,234 individuals (HHS portal count; OCR investigation found 31,800 individuals actually exposed). ePHI stored on a network server was publicly accessible via internet search engines (e.g. Google) from Feb 1, 2011 to Feb 13, 2012, due to default file-sharing application settings left unconfigured. Data exposed included patient names, health statuses, diagnoses, and demographics. SJH settled with OCR for $2,140,500 and agreed to a corrective action plan.