The Children's Hospital of Philadelphia
ent_019e0d5d1d0db9a8e01c7bd8f1be364a
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
5,368
as filed · HHS OCR PA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Children's Hospital of Philadelphia
- Normalized
- the children s hospital of philadelphia— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900N2KNSY5WTR1Q61
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- chop.edu
Disclosure history (3)newest first
- PAHHS OCRas victim2018-10-23
The Children's Hospital of Philadelphia (CHOP) reported to HHS on 2018-10-23 a Hacking/IT Incident affecting 5,368 individuals. On August 23, 2019, a phishing email sent to 679 Outlook users enabled an unauthorized actor to access a physician's email account and the accounts of five employees who forwarded work email externally. The compromised account contained PHI including demographic and clinical information of approximately 5,368 patients. CHOP responded by disabling the account, recalling phishing emails, blocking the phishing site, resetting credentials, notifying affected individuals, and offering credit monitoring. Staff phishing training and a risk assessment update followed. OCR obtained documented assurances of corrective action.
- 🦬Montana State AGas victim2018-10-23
Children's Hospital of Philadelphia (CHOP) reported a data breach to the Montana Attorney General. The breach was reported on 2018-10-23. The breach occurred from 8/23/2018 to 8/24/2018. 1 Montana residents were affected.
- PAHHS OCRas victim2009-11-24
The Children's Hospital of Philadelphia (CHOP), a PA-based Healthcare Provider, reported to HHS OCR on 2009-11-24 a Theft breach affecting 943 individuals. A laptop was stolen from a hospital employee's vehicle. The device contained PHI including names, contact information, dates of birth, Social Security numbers, medical record numbers, diagnosis codes, and billing code descriptions. CHOP completed laptop encryption, revised its security policies, and retrained staff. OCR obtained assurances of corrective action. Breached information located on Laptop.