Monongalia Health System, Inc.
ent_019e0d62f189fb07cd7c3a63bf1ce2c2
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
398,164
as filed · HHS OCR WV
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Monongalia Health System, Inc.
- Normalized
- monongalia health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300S8M6M2AIOH5Z62
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🦬Montana State AGas victim2025-05-06
Monongalia Health System, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2025-05-06. The breach occurred on 10/22/2024. 1 Montana residents were affected.
- WVHHS OCRas victim2025-05-03
Monongalia Health System, Inc. (WV) reported to HHS OCR on 2025-05-03 an Unauthorized Access/Disclosure breach affecting 4,895 individuals. Breached information was located on Email. No business associate was identified as involved. No further details were provided in the web description.
- 🐻California State AGas victim2022-02-28
Monongalia Health System, Inc. disclosed a cybersecurity incident occurring between Dec 8-19, 2021, involving unauthorized access to IT systems. The breach potentially exposed patient, provider, and employee data, including names, SSNs, medical records, and financial account numbers. Mon Health took systems offline, reset passwords, engaged forensic investigators, and notified law enforcement. Affected individuals were offered one year of Experian IdentityWorks.
- WVHHS OCRas victim2021-12-21
Monongalia Health System, Inc. (WV) reported to HHS on 2021-12-21 a Hacking/IT Incident (email phishing attack) affecting 398,164 individuals. Multiple employees were victims of the phishing attack, exposing PHI including names, addresses, Social Security numbers, health insurance and claims information, and treatment information. The CE notified HHS, affected individuals, and the media, posted substitute notice on its website, implemented additional technical safeguards, and provided complimentary credit monitoring. Breached information located on Email.