Advocate Aurora Health, Inc.
ent_019e0be5fc36115d15cde13633e8fa9a
Disclosures
20
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
3,000,000
nationwide · HHS OCR WI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Advocate Aurora Health, Inc.
- Normalized
- advocate aurora health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900UH8G09UE2PV855
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- advocateaurorahealth.org
Disclosure history (20)newest first
- Illinois State AGas victim2023-01-01
ADVOCATE AURORA HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-085). The register records the breach as discovered on January 31, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- WISCONSINHHS OCRas victim2022-10-14
Advocate Aurora Health reported to HHS on 2022-10-14 a Unauthorized Access/Disclosure affecting 3,000,000 individuals. Breached information located on Electronic Medical Record. Web tracking technology transferred PHI to unauthorized recipients.
- Illinois State AGas victim2022-01-01
ADVOCATE AURORA HEALTH filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-343). The register records the breach as discovered on March 24, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- WISCONSINHHS OCRas victim2021-12-28
Advocate Aurora Health (WI) reported to HHS on 2021-12-28 a Loss affecting 1,729 individuals. A document containing PHI — including names, diagnoses, and other treatment information — was lost in the mail. Breached information was on Paper/Films. The CE notified HHS, affected individuals, and media; provided credit monitoring; sanctioned the responsible employee; and implemented technical safeguards.
- WISCONSINHHS OCRas victim2021-07-16
Advocate Aurora Health reported to HHS on 2021-07-16 a Hacking/IT Incident affecting 68,707 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, SSNs, and medical data. Credit monitoring was provided.
- Massachusetts State AGas victim2021-07-16
Advocate Aurora Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-16. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2021-01-01
ADVOCATE AUROR HEALTH filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-272). The register records the breach as discovered on July 6, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
ADVOCATE AURORA HEALTH filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-527). The register records the breach as discovered on October 29, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
ADVOCATE AURORA HEALTH filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-429). The register records the breach as discovered on May 17, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- WISCONSINHHS OCRas victim2020-09-04
Advocate Aurora Health reported to HHS on 2020-09-04 a Unauthorized Access/Disclosure affecting 2979 individuals. Breached information located on Paper/Films. Documents containing PHI were left unprotected during a facility move.
- WISCONSINHHS OCRas victim2020-08-14
Advocate Aurora Health reported to HHS on 2020-08-14 a Unauthorized Access/Disclosure affecting 1907 individuals. Breached information located on Paper/Films. An employee mailed documents containing PHI (names, addresses, health insurance, claims, treatment info) to wrong recipients. CE provided credit monitoring and implemented administrative safeguards.
- WISCONSINHHS OCRas victim2020-04-16
Advocate Aurora Health (WI) reported to HHS OCR on 2020-04-16 a Hacking/IT Incident affecting 27,137 individuals. Several employees were victims of an email phishing scheme. PHI exposed via Email included names, addresses, dates of birth, driver's license numbers, SSNs, passport numbers, full face photographs, claims and financial information, health insurance information, diagnoses/conditions, lab results, medications prescribed, and other treatment information. Identity theft protection was offered; additional safeguards and workforce retraining were implemented.
- Montana State AGas victim2020-02-20
Advocate Aurora Health notified Montana AG of a phishing incident occurring Jan 1-9, 2020. Attackers gained access to employee email credentials via phishing, potentially exposing patient PII, PHI, SSNs, and financial data. Incident discovered Jan 9, 2020. Notifications sent April 17, 2020. Response included forensic investigation, credential resets, and credit monitoring offers.
- Montana State AGas victim2020-02-20
Advocate Aurora Health disclosed a security incident in January 2020 where unauthorized access was gained via a phishing campaign targeting employee credentials. The intruder accessed a human resource system containing PII of current and former employees, including SSNs, bank account details, birth dates, and home addresses. Advocate Aurora changed credentials, locked out the intruder, launched an investigation, notified law enforcement, and offered one year of Experian IdentityWorks.
- Indiana State AGas victim2020-02-20
Advocate Aurora Health reported a data breach to the Indiana Attorney General. The breach occurred on 2020-01-01 and was reported on 2020-02-20. 1,133 Indiana residents were affected. 176,000 individuals affected in total.
- Massachusetts State AGas victim2020-02-19
Advocate Aurora Health 3AAH ́ reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-02-19. 65 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2020-02-19
Advocate Aurora Health notified the NH AG of a phishing incident where credentials were compromised, leading to payroll diversion and access to PeopleSoft. Discovered Jan 9, 2020. ~176,000 employees affected nationwide; 13 NH residents. Data included SSNs, bank info, and PII. Law enforcement notified.
- Illinois State AGas victim2020-01-01
ADVOCATE AURORA HEALTH - DUPLICATE # 20-69 filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-171). The register records the breach as discovered on January 1, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
ADVOCATE AUROA HEALTH filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-293). The register records the breach as discovered on June 18, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
ADVOCATE AURORA HEALTH filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-069). The register records the breach as discovered on January 9, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.