RUSH UNIVERSITY MEDICAL CENTER
ent_019e0c91d8c70ff741737f34a2d81d28
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
44,924
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- RUSH UNIVERSITY MEDICAL CENTER
- Normalized
- rush university medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- ZF7C375GL43TFX8CCS02
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- rush.edu
- Corporate parent
- Rush System for Health— per GLEIF relationship records
Disclosure history (3)newest first
- ILHHS OCRas victim2019-02-28
Rush University Medical Center reported to HHS on 2019-02-28 a Unauthorized Access/Disclosure affecting 44,924 individuals. Breached information located on Network Server. A business associate, MiraMed Global Services, Inc., reported that an employee improperly disclosed PHI (names, addresses, DOB, SSN, insurance info) to a personal email account with intent to sell. The employee was sanctioned and law enforcement notified.
- 🦬Montana State AGas victim2019-02-28
Rush University Medical Center reported a data breach to the Montana Attorney General. The breach was reported on 2019-02-28. The breach occurred from 5/1/2018 to 1/22/2019.
- ILHHS OCRas victim2015-11-06
On September 9, 2015, business associate Standard Register erroneously mailed retirement announcements on behalf of Rush University Medical Center (IL), resulting in misdirected letters sent to 1,529 wrong patients. Breached information (paper/films) included patients' names only. The covered entity notified HHS, media, and affected individuals, published substitute notice, entered into a BA agreement with Standard Register, and established quality-control procedures for mass mailings. OCR confirmed corrective actions were implemented.