BAYLOR COLLEGE OF MEDICINE
ent_019e0d6488424046cc1bb8f27762ccd9
Disclosures
10
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,586
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BAYLOR COLLEGE OF MEDICINE
- Normalized
- baylor college of medicine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006UKJHZXSM3H989
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bcm.edu
Disclosure history (10)newest first
- TEXASHHS OCRas victim2024-03-29
Baylor College of Medicine reported to HHS on 2024-03-29 a Hacking/IT Incident affecting 801 individuals. Breached information located on Email. An employee of its business associate was the subject of an email phishing scheme that affected PHI including names and dates of birth.
- TEXASHHS OCRas victim2023-07-28
Baylor College of Medicine reported to HHS on 2023-07-28 a Hacking/IT Incident affecting 505 individuals. Breached information located on Network Server. The business associate was the victim of a cybersecurity incident affecting PHI including names, DOB, SSNs, and lab results.
- TEXASHHS OCRas victim2020-09-09
Baylor College of Medicine reported to HHS on 2020-09-09 a Hacking/IT Incident affecting 4586 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI (names, DOB, treatment info). CE notified HHS, individuals, and media.
- Massachusetts State AGas victim2017-11-20
Baylor College of Medicine reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-11-20. 93 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-11-08
Baylor College of Medicine discovered in late October 2016 that a database containing applicant information (names and SSNs) may have been compromised. In October 2017, the institution learned the data had been published on a public website by an unknown third party. Approximately 1 New Hampshire resident was affected. BCM corrected the vulnerability, engaged an outside consultant, and offered one year of identity monitoring via Kroll.
- Montana State AGas victim2017-11-08
Baylor College of Medicine notified Montana residents of a data breach where applicant personal information (names, SSNs) was exposed via unauthorized access to a database. The incident was discovered in October 2016, and exposure was confirmed in October 2017. The college engaged Kroll to provide one year of identity monitoring services to affected individuals.
- Montana State AGas victim2016-11-30
Baylor College of Medicine notified Montana residents of a data breach in late October 2016. A database containing applicant information was compromised, exposing names and Social Security numbers. The college engaged Kroll to provide one year of free identity monitoring services to affected individuals.
- New Hampshire State AGas victim2016-11-30
Baylor College of Medicine notified the NH Attorney General on Nov 30, 2016, of a late October 2016 database compromise exposing applicant PII (names, SSNs). BCM engaged Kroll for identity monitoring.
- TEXASHHS OCRas victim2015-08-07
Baylor College of Medicine reported to HHS on 2015-08-07 a Theft affecting 1004 individuals. Breached information located on Other Portable Electronic Device, Paper/Films. A physician's backpack containing unencrypted drives and a notebook with pediatric patient PHI was stolen from an automobile.
- TEXASHHS OCRas victim2010-07-30
Baylor College of Medicine reported to HHS OCR on 2010-07-30 a Theft affecting 1,646 individuals (later revised to ~1,618). An unencrypted laptop was stolen from an administrative office. The laptop contained PHI of pediatric cardiology patients—names, medical record numbers, dates of service, diagnoses, and dates of birth. Baylor and Texas Children's Hospital jointly notified affected individuals and local media after a delay due to a law enforcement request. Following OCR's investigation, the CE revised IT policies and modified physical safeguards. Breached information located on Laptop.