AU MEDICAL CENTER, INC.
ent_019e0b3f4627edf3036d63333140b62e
Disclosures
5
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
472,413
nationwide · HHS OCR GA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AU MEDICAL CENTER, INC.
- Normalized
- au medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300Z7786P5N3KXT71
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- GEORGIAHHS OCRas victim2018-08-16
AU Medical Center, INC reported to HHS on 2018-08-16 a Hacking/IT Incident affecting 472413 individuals. Breached information located on Email. Employees were victims of an email phishing attack exposing ePHI including names, addresses, DOB, SSN, driver's license numbers, financial info, and medical records. The CE implemented additional safeguards and retrained employees.
- New Hampshire State AGas victim2017-09-18
AU Medical Center, Inc. and Augusta University notified the NH Attorney General that a phishing attack compromised medical faculty email accounts between April 20-21, 2017. The incident affected one New Hampshire resident. Compromised data included PHI, SSNs, and financial account numbers. The organization disabled accounts, reset passwords, retained forensic investigators, and offered credit monitoring.
- GEORGIAHHS OCRas victim2017-09-15
AU Medical Center, Inc. (GA, healthcare provider) reported to HHS OCR on 2017-09-15 that multiple employees were victims of an email phishing attack, exposing ePHI of 6,109 individuals. Compromised data included names, addresses, dates of birth, SSNs, financial information, driver's license numbers, medical record numbers, health insurance and prescription information, and diagnoses/treatment information. The covered entity notified HHS, affected individuals, the media, and provided substitute notice on its website. Remediation included additional administrative and technical safeguards and employee retraining on email security.
- New Hampshire State AGas victim2017-05-26
AU Medical Center, Inc. notified the NH Attorney General that a phishing attack compromised medical faculty email accounts between Sept 7-9, 2016. The incident affected 1 NH resident, exposing PHI including name, SSN, DOB, and medical record numbers. Notification was sent May 26, 2017, offering credit monitoring.
- GEORGIAHHS OCRas victim2017-05-26
On September 7, 2016, a cyber-attacker sent a phishing email to Augusta University Medical Center, Inc. (GA) and obtained employee usernames and passwords. The attacker accessed a self-service portal to redirect employee paychecks. PHI of 4,690 individuals was exposed, including addresses, dates of birth, medical record numbers, insurance, prescription and treatment information, and, for some, Social Security numbers. HHS breach submission filed 2017-05-26; 5,600 individuals listed as affected. Breached information located in Email.