EPISCOPAL HEALTH SERVICES INC.
ent_019e0cdeca0d46ac4d1db7a7fffa2fe5
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
218,055
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- EPISCOPAL HEALTH SERVICES INC.
- Normalized
- episcopal health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300C2MBPWRSQZWG51
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- New Hampshire State AGas victim2019-04-22
Episcopal Health Services Inc. notified the NH AG of unauthorized access to employee email accounts between Aug 28 and Oct 5, 2018. Discovered Sept 18, 2018. 6 NH residents affected; PHI and SSN exposed. Response included forensic investigation, credential resets, and credit monitoring.
- Massachusetts State AGas victim2019-04-19
Episcopal Health Services reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-04-19. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- NEW YORKHHS OCRas victim2018-11-19
Episcopal Health Services, Inc. (NY) reported to HHS on 2018-11-19 a Hacking/IT Incident (email phishing scheme) affecting 218,055 individuals. Numerous employees were victims of a phishing attack that compromised ePHI stored in email systems. Exposed data included names, dates of birth, addresses, Social Security numbers, driver's license numbers, financial information, diagnoses, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media, and provided free credit monitoring. New administrative and technical safeguards were implemented; OCR obtained corrective-action assurances.
- NEW YORKHHS OCRas victim2015-06-25
On June 25, 2015, Episcopal Health Services Inc. reported a data breach to HHS affecting 509 individuals. The incident was a result of theft by an employee of its business associate, Zotec Partners, LLC, who sold patient data. The compromised information included names, Social Security numbers, dates of birth, addresses, and detailed protected health information. In response, the business associate implemented enhanced security controls and training. OCR opened an investigation into the matter.