BEAUMONT HEALTH
ent_019e0cbfef333f5b1e55c920635ef10a
Disclosures
12
HHS OCR · State AG · 5 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
112,211
nationwide · HHS OCR MI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BEAUMONT HEALTH
- Normalized
- beaumont health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300C7Q6EVOWMBI662
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- MICHIGANHHS OCRas victim2021-08-27
Beaumont Health reported to HHS on 2021-08-27 a Hacking/IT Incident affecting 1568 individuals. Breached information located on Network Server. The business associate was the victim of a cyber-attack affecting ePHI including names, addresses, birthdates, diagnoses, and treatment information.
- New Hampshire State AGas victim2021-03-03
Beaumont Health Foundation notified the New Hampshire Attorney General of a security incident involving its third-party provider, Blackbaud. The incident involved an attempted ransomware attack where data was exfiltrated between Feb 7 and May 20, 2020. Beaumont determined on Jan 13, 2021, that limited personal information (names, bank account numbers) of approximately 2 NH residents was affected. Beaumont engaged forensic experts, suspended data sharing, and notified residents.
- Massachusetts State AGas victim2021-02-25
Beaumont Health Foundation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-02-25. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-02-17
Beaumont Health Foundation notified Montana AG of a third-party breach involving Blackbaud. A ransomware attack occurred Feb-May 2020. Data exfiltrated may include PII (names, addresses). SSN and EHR data were not impacted. Beaumont engaged forensic experts and suspended data sharing.
- New Hampshire State AGas victim2020-08-10
Beaumont Health notified the NH AG of a phishing incident affecting 1 NH resident. Unauthorized access to email accounts occurred Jan 3-29, 2020. PHI (diagnosis, care date, age) was accessed. Discovered June 5, 2020. No evidence of misuse. Remediation included MFA improvements and workforce retraining.
- MICHIGANHHS OCRas victim2020-07-28
Beaumont Health reported to HHS on 2020-07-28 a hacking/IT incident affecting 6,073 individuals. The breach resulted from an email phishing scheme targeting employees. Breached information, located on email and network servers, included names, addresses, dates of birth, clinical information, and medical record numbers.
- Massachusetts State AGas victim2020-04-20
Beaumont Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-04-20. 17 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2020-04-17
Beaumont Health notified Montana residents of a phishing incident where unauthorized access to employee email accounts occurred between May 23 and June 3, 2019. The breach was discovered on March 29, 2020. No evidence of data misuse was found, but personal and protected health information may have been accessed.
- MICHIGANHHS OCRas victim2020-04-17
Beaumont Health reported to HHS on 2020-04-17 a Hacking/IT Incident affecting 112,211 individuals. Breached information located on Email. Employees were victims of an email phishing attack affecting ePHI including names, addresses, SSNs, clinical info, and medical record numbers.
- New Hampshire State AGas victim2020-01-27
Beaumont Health notified the NH Attorney General of an insider incident where a former employee accessed patient PHI without authorization on Dec 10, 2019. One NH resident's data (name, SSN, DOB, medical info) was accessed. The employee was terminated. Beaumont offered 12 months of credit monitoring and notified the individual on Jan 24, 2020.
- MICHIGANHHS OCRas victim2020-01-24
Beaumont Health (Michigan) reported to HHS on 2020-01-24 an Unauthorized Access/Disclosure affecting 1,182 individuals. An employee impermissibly accessed PHI stored in Electronic Medical Records, including names, addresses, dates of birth, Social Security numbers, medical record numbers, diagnoses/conditions, and other treatment information. The employee was sanctioned, staff retrained, and additional administrative and technical safeguards implemented. OCR obtained assurances that corrective actions were completed.
- Illinois State AGas victim2020-01-01
BEAUMON HEALTH filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-021). The register records the breach as discovered on December 10, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- BEAUMONT HEALTH’s filing is one of at least 175 in the BLACKBAUD, INC. supply-chain incident (2020).