NORTON HEALTHCARE, INC.
ent_019e0d66355087339c2a8970248a13bd
Disclosures
12
State AG · HHS OCR · Leak Site · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,500,000
nationwide · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- NORTON HEALTHCARE, INC.
- Normalized
- norton healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006Y7F6PDF56ZN56
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- nortonhealthcare.com
Disclosure history (12)newest first
- Oregon State AGas victim2023-12-13
Norton Healthcare Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-12-13. The breach occurred during 5/7/2023 - 5/9/2023. The breach was discovered on 5/9/20237/7/2023. 2,500,000 individuals were affected. Notice was sent on 12/8/202312/21/2023.
- New Hampshire State AGas victim2023-12-11
Norton Healthcare, Inc. notified the NH AG of a ransomware incident discovered on May 9, 2023. Unauthorized access to network storage occurred May 7-9, 2023. Data exfiltrated included PII, SSNs, health info, and financial data for ~356 NH residents. Notifications sent Dec 8, 2023. No ransom paid. Systems restored from backups.
- Maine State AGas victim2023-12-08
Norton Healthcare, Inc. reported an external system breach (hacking) occurring between May 7 and May 9, 2023. The incident affected approximately 2,500,000 individuals, including 385 Maine residents. Acquired data included names combined with driver's license numbers. Norton Healthcare notified affected individuals in writing on December 8, 2023, and provided 24 months of credit monitoring and identity theft protection through Kroll.
- Montana State AGas victim2023-12-08
Norton Healthcare, Inc. disclosed a ransomware attack discovered on May 9, 2023, involving unauthorized access to network storage devices between May 7-9, 2023. The incident impacted personal and health information of patients, employees, and dependents, including SSNs, DOBs, and financial data. The company notified law enforcement, engaged forensic experts, and provided two years of identity monitoring via Kroll.
- California State AGas victim2023-12-08
Norton Healthcare, Inc. experienced a ransomware attack discovered on May 9, 2023. Unauthorized access to network storage devices occurred between May 7 and May 9, 2023. Affected data included PHI, PII (SSN, DOB, contact info), financial account numbers, and government IDs for patients, employees, and dependents. Norton Healthcare notified federal law enforcement, engaged forensic experts, terminated access, and offered two years of identity monitoring via Kroll.
- Washington State AGas victim2023-12-08
Norton Healthcare, Inc. disclosed a ransomware attack discovered on May 9, 2023, involving unauthorized access to network storage devices between May 7-9, 2023. The incident impacted approximately 1,872 Washington residents, exposing PII, PHI, SSNs, and financial data. Norton notified the FBI, engaged forensic investigators, restored systems from backups, and offered 24 months of credit monitoring.
- South Carolina State AGas victim2023-12-08
Norton Healthcare, Inc. reported a ransomware attack discovered on May 9, 2023, involving unauthorized access to network storage devices between May 7-9, 2023. The incident impacted personal information of patients, employees, and dependents, including names, SSNs, DOBs, health info, and financial data. Norton Healthcare notified law enforcement, engaged forensic experts, and provided two years of identity monitoring via Kroll.
- Massachusetts State AGas victim2023-12-08
Norton Healthcare, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-08. 1,324 Massachusetts residents were affected. The report records the breach type as electronic.
- Vermont State AGas victim2023-12-08
Norton Healthcare, Inc. reported a ransomware incident discovered on May 9, 2023, involving unauthorized access to network storage devices between May 7-9, 2023. The incident impacted personal information including names, SSNs, DOBs, health info, and financial account numbers. Norton Healthcare notified law enforcement, engaged forensic experts, and offered two years of identity monitoring via Kroll.
- KENTUCKYHHS OCRas victim2023-07-07
Norton Healthcare Inc. (KY) reported to HHS OCR on 2023-07-07 a ransomware incident affecting 2,500,000 individuals. Breached information was located on network servers and included names, addresses, dates of birth, Social Security numbers, and financial and health insurance information. The organization notified HHS, affected individuals, the media, and posted substitute notice on its website. Free credit monitoring was offered and additional administrative, technical, and security safeguards were implemented.
- GLOBALLeak Siteas victim2023-05-25
Norton Healthcare is a Kentucky health care system with more than 40 clinics and hospitals in and around Louisville, Kentucky. The hospital and health care system is the Louisville area's third largest private employer, located at more than 140 locations throughout Greater Louisville and Southern Indiana. The Louisville-based system includes six hospitals (one being in Madison, Indiana) with 1,993 licensed beds, eight outpatient centers, 18 Norton Immediate Care Centers, over 1,700 employees, over 1,500 employed medical providers, and approximately 2,000 total physicians on its medical staff. According to Business First of Louisville, Norton Healthcare is the Louisville area's third largest employer, with more than 17,000 employees. Norton Healthcare employs some 4,000 nurses and has nearly 2,000 affiliated physicians. Additionally, Norton Healthcare has programs in place to support nursing students attending both public and private universities in Kentucky and Indiana. Revenue : 2.6B USD
- Illinois State AGas victim2023-01-01
NORTON HEALTHCARE, INC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-830). The register records the breach as discovered on May 7, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.