THE BRIGHAM AND WOMEN'S HOSPITAL, INC.
ent_019e0b3cc46fab0aada11cbfc8ee4fac
Disclosures
5
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
1,009
as filed · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE BRIGHAM AND WOMEN'S HOSPITAL, INC.
- Normalized
- the brigham and women s hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900H6XXN3KL4Y3K71
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- MASSACHUSETTSHHS OCRas victim2023-08-04
Brigham and Women's Hospital reported to HHS on 2023-08-04 a Unauthorized Access/Disclosure affecting 987 individuals. Breached information located on Network Server. Graphs posted to the Internet contained a link exposing PHI (names, birthdates, diagnoses, lab results, medications). The CE implemented additional safeguards and retrained staff.
- MASSACHUSETTSHHS OCRas victim2020-12-08
Brigham and Women’s Hospital reported to HHS on 2020-12-08 a Unauthorized Access/Disclosure affecting 882 individuals. Breached information located on Email. An employee sent a newsletter to 882 recipients without using blind copy, exposing all email addresses. The entity notified HHS, affected individuals, and the media, sanctioned the employee, and implemented additional safeguards.
- MASSACHUSETTSHHS OCRas victim2016-01-11
Brigham and Women's Hospital (MA) reported to HHS on 2016-01-11 a Hacking/IT Incident affecting 1,009 individuals. An unauthorized individual obtained employee network credentials and used them to access the employee's work email account and potentially a personal Gmail account containing work-related emails. PHI potentially accessed included names, birthdates, medical record numbers, provider names, dates of service, diagnoses/conditions, and treatment information. Breached information located on Email. OCR obtained assurances of corrective actions.
- FEDERALHHS OCRas victim2014-11-17
An employee of Brigham & Women’s Hospital had an encrypted laptop and cell phone stolen during an armed robbery and was forced to disclose the password and encryption keys. The devices contained the protected health information (PHI) of 999 individuals, including names, medical records numbers, age, and diagnostic information. In response to the investigation, the hospital initiated a new enterprise-wide risk analysis.
- MASSACHUSETTSHHS OCRas victim2012-11-26
Brigham and Women's Hospital (MA) reported to HHS OCR on 2012-11-26 a Theft breach affecting 615 individuals. The breached information was located on a Desktop Computer. No business associate was involved.