Allina Health System
ent_019e0bc941b35f7d963934e4ae900d11
Disclosures
7
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
199,389
nationwide · HHS OCR MN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Allina Health System
- Normalized
- allina health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001V00JCD7SQ0G44
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- allinahealth.org
Disclosure history (7)newest first
- MNHHS OCRas victim2024-05-06
Allina Health System (MN) reported to HHS on 2024-05-06 an Unauthorized Access/Disclosure affecting 715 individuals. An employee impermissibly accessed the PHI of those individuals via Electronic Medical Record systems. PHI involved included demographic, financial, and clinical information. The covered entity notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards.
- MNHHS OCRas victim2023-04-28
Allina Health reported to HHS on 2023-04-28 a Unauthorized Access/Disclosure affecting 1042 individuals. Breached information located on Network Server.
- MNHHS OCRas victim2020-09-11
Allina Health reported to HHS on 2020-09-11 a Hacking/IT Incident affecting 199,389 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, DOB, email, phone, and treatment info. CE notified HHS, individuals, and media.
- MNHHS OCRas victim2017-02-23
Allina Health System (Minneapolis Heart Institute) reported to HHS OCR on 2017-02-23 an Improper Disposal breach affecting 776 individuals. PHI on Paper/Films was placed in a recycling bin and emptied rather than shredded as planned. Breach was discovered on January 20, 2017. Exposed PHI included names, addresses, dates of birth, SSNs, Medicare IDs, insurance IDs, clinical diagnoses, and lab results. OCR obtained assurances that corrective actions — new policies, procedures, and employee training — were implemented.
- MNHHS OCRas victim2015-12-23
Allina Health (MN) reported to HHS on 2015-12-23 an Improper Disposal breach affecting 6,195 individuals. On October 27, 2015, a janitorial vendor erroneously placed patients' PHI in a trash dumpster; breached information was on Paper/Films and included financial, demographic, and clinical data. The CE updated its physical safeguards policy, educated staff, and worked with Iron Mountain (its PHI disposal BA) on corrective actions. OCR confirmed implementation of remediation measures.
- FEDERALHHS OCRas victim2015-04-06
Allina Health reported that it erroneously mailed letters and preventative screening kits to incorrect recipients, affecting 838 individuals. The protected health information involved included individuals' names. The incident, reported on April 6, 2015, involved paper documents and films. In response, the company retrained employees and implemented a new, more secure mailing workflow.
- MNHHS OCRas victim2013-11-04
Allina Health reported to HHS on 2013-11-04 a Unauthorized Access/Disclosure affecting 3807 individuals. Breached information located on Electronic Medical Record. An employee improperly accessed PHI including names, addresses, DOB, medical conditions, medications, and lab results.