Children's Hospital Colorado
ent_019e0bd52cd1ec77c202eee262e28796
Disclosures
5
HHS OCR enforcement · HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,370
nationwide · HHS OCR CO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Children's Hospital Colorado
- Normalized
- children s hospital colorado— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300T4XJYM3J9UZI27
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- childrenscolorado.org
Disclosure history (5)newest first
- FEDERALHHS OCR enforcementas victim2024-12-05
HHS OCR imposed a $548,265 civil monetary penalty on Children’s Hospital Colorado for HIPAA Privacy and Security Rules violations following two breaches involving email phishing and cyberattacks. The investigation found that multi-factor authentication was disabled on one account and workforce members granted access to unknown third parties on others. The hospital waived its right to a hearing and did not contest the findings.
- COLORADOHHS OCRas victim2020-07-27
Children's Hospital Colorado reported to HHS OCR on 2020-07-27 a Hacking/IT Incident affecting 2,553 individuals, with breached information located in Email accounts. OCR investigated two related phishing incidents (2017 and 2020): one compromising an email account (3,370 individuals' PHI) due to disabled MFA, and another where workforce members granted unknown third parties access to three email accounts (10,840 individuals' PHI). OCR found HIPAA Privacy and Security Rule violations. A civil money penalty of $548,265 was imposed in 2024.
- Illinois State AGas victim2020-01-01
CILDREN'S HOSPITAL COLORADO filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-379). The register records the breach as discovered on July 22, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
CHILDREN'S HOSPITAL COLORADO filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-271). The register records the breach as discovered on June 22, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- COLORADOHHS OCRas victim2017-09-08
Children's Hospital Colorado reported to HHS OCR on 2017-09-08 a Hacking/IT Incident (email phishing) affecting 3,370 individuals' PHI stored in email accounts. OCR investigation found MFA was disabled on a compromised account. OCR imposed a $548,265 civil money penalty. Breached info located in Email. No business associate was involved. The entity is a pediatric hospital, so minor patient records are implicated.