MEMORIAL HERMANN HEALTH SYSTEM
ent_019e0d2a140b6da1e9f67ebe21fff4bb
Disclosures
6
HHS OCR · HHS OCR enforcement · State AG · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
10,604
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MEMORIAL HERMANN HEALTH SYSTEM
- Normalized
- memorial hermann health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300EWQQX32WNN5Z26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- memorialhermann.org
Disclosure history (6)newest first
- TEXASHHS OCRas victim2021-03-31
Memorial Hermann Health System (TX) reported to HHS OCR on 2021-03-31 an Unauthorized Access/Disclosure affecting 1,893 individuals. A business associate employee uploaded PHI to the Internet, making it publicly viewable. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnoses, claims, health insurance information, and other treatment information. Breached information was located on a Network Server. The BA offered credit monitoring and implemented additional technical safeguards.
- TEXASHHS OCRas victim2019-07-02
Memorial Hermann Health System reported to HHS on 2019-07-02 a Unauthorized Access/Disclosure affecting 507 individuals. Breached information located on Email. A workforce member inadvertently emailed a spreadsheet containing PHI (names, medical record numbers, financial/insurance info, clinical info). The CE sanctioned the employee, revised procedures, and contacted the recipient to ensure deletion.
- TEXASHHS OCRas victim2019-05-13
Memorial Hermann Health System reported to HHS on 2019-05-13 a Unauthorized Access/Disclosure affecting 604 individuals. Breached information located on Electronic Medical Record, Email. An employee fraudulently used patient financial information for personal use.
- FEDERALHHS OCR enforcementas victim2017-05-10
Memorial Hermann Health System (MHHS), a not-for-profit health system in Southeast Texas, agreed to pay $2.4 million to HHS to settle potential HIPAA Privacy Rule violations involving the disclosure of patient information. MHHS also adopted a comprehensive corrective action plan.
- Massachusetts State AGas victim2014-09-03
Memorial Hermann Health System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-09-03. 1 Massachusetts residents were affected.
- TEXASHHS OCRas victim2014-08-29
Memorial Hermann Health System reported to HHS on 2014-08-29 a Unauthorized Access/Disclosure affecting 10,604 individuals. Breached information located on Desktop Computer. A workforce member inappropriately accessed PHI.