CHARLESTON AREA MEDICAL CENTER, INC.
ent_019e0bbb7a4956bd3eb66244d64f81b0
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
67,413
as filed · HHS OCR WV
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHARLESTON AREA MEDICAL CENTER, INC.
- Normalized
- charleston area medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300971R121Y3SNQ15
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🍁Vermont State AGas victim2025-02-14
Charleston Area Medical Center notified Vermont AG of a phishing incident discovered Oct 2, 2024. An unauthorized party accessed a single user's email mailbox between Oct 2-3, 2024. Impacted data included names, DOB, driver's license, health info, and insurance info. CAMC engaged forensic experts, provided phishing training, enhanced safeguards, and offered 24 months of identity theft protection.
- WVHHS OCRas victim2025-02-14
Charleston Area Medical Center (WV) reported to HHS on 2025-02-14 a Hacking/IT Incident (email phishing) affecting 67,413 individuals. An employee was the subject of a phishing attack that compromised PHI stored in Email systems. Exposed data included names, Social Security numbers, driver's license numbers, birthdates, addresses, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, and the media, and responded with additional administrative and technical safeguards and employee retraining.
- 🏎️Indiana State AGas victim2025-02-14
Charleston Area Medical Center reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-02 and was reported on 2025-02-14. 35 Indiana residents were affected. 67,413 individuals affected in total.
- WVHHS OCRas victim2022-03-28
Charleston Area Medical Center, Inc. reported to HHS on 2022-03-28 a Hacking/IT Incident affecting 54,000 individuals. Breached information located on Email. Employees were victims of a phishing attack exposing PHI including names, DOB, MRNs, SSNs, and financial info. CE provided credit monitoring and implemented technical safeguards.