BAYLOR COLLEGE OF MEDICINE
ent_019e0d6488424046cc1bb8f27762ccd9
Disclosures
5
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
4,586
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BAYLOR COLLEGE OF MEDICINE
- Normalized
- baylor college of medicine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006UKJHZXSM3H989
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bcm.edu
Disclosure history (5)newest first
- TEXASHHS OCRas victim2020-09-09
Baylor College of Medicine reported to HHS on 2020-09-09 a Hacking/IT Incident affecting 4586 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI (names, DOB, treatment info). CE notified HHS, individuals, and media.
- ⛰️New Hampshire State AGas victim2017-11-08
Baylor College of Medicine notified the New Hampshire Attorney General in November 2017 regarding a data breach discovered in late October 2016. An unauthorized party accessed a database containing applicant information, including names and Social Security numbers. The data was later found on a public website in October 2017. Approximately 1 New Hampshire resident was affected. BCM engaged Kroll to provide one year of credit monitoring services.
- 🦬Montana State AGas victim2017-11-08
Baylor College of Medicine reported a data breach to the Montana Attorney General. The breach was reported on 2017-11-08. The breach occurred from 10/15/2016 to 10/31/2017. 4 Montana residents were affected.
- 🦬Montana State AGas victim2016-11-30
Baylor College of Medicine reported a data breach to the Montana Attorney General. The breach was reported on 2016-11-30. The breach occurred from 10/15/2016 to 10/31/2016. 1 Montana residents were affected.
- TEXASHHS OCRas victim2010-07-30
Baylor College of Medicine reported to HHS OCR on 2010-07-30 a Theft affecting 1,646 individuals (later revised to ~1,618). An unencrypted laptop was stolen from an administrative office. The laptop contained PHI of pediatric cardiology patients—names, medical record numbers, dates of service, diagnoses, and dates of birth. Baylor and Texas Children's Hospital jointly notified affected individuals and local media after a delay due to a law enforcement request. Following OCR's investigation, the CE revised IT policies and modified physical safeguards. Breached information located on Laptop.