BANNER HEALTH
ent_019e0d6c045dbf3afeebe8e6b8a946d6
Disclosures
7
State AG · HHS OCR · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
3,623,140
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BANNER HEALTH
- Normalized
- banner health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- PLD0E0WJKFN8IZJ2WD85
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bannerhealth.com
Disclosure history (7)newest first
- 🌲Washington State AGas victim2016-08-03
Banner Health, a health sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2016-07-13 and filed notice on 2016-08-03. 7,916 Washington residents were affected. 21 days elapsed between awareness and notification. 26 days to identify the breach.
- ⛰️New Hampshire State AGas victim2016-08-03
Banner Health notified the New Hampshire Attorney General on August 3, 2016, regarding unauthorized access to patient servers occurring on June 17, 2016. The breach affected approximately 379 New Hampshire residents, exposing names, SSNs, health information, and financial data. Banner provided credit monitoring and established a call center.
- 🦬Montana State AGas victim2016-08-03
Banner Health reported a data breach to the Montana Attorney General. The breach was reported on 2016-08-03. The breach occurred from 6/23/2016 to 7/7/2016. 2,155 Montana residents were affected.
- 🐻California State AGas victim2016-08-03
Banner Health disclosed two cybersecurity incidents in California in 2016. The first involved unauthorized access to patient servers from June 17 to July 7, 2016, exposing PHI, SSNs, and demographics. The second involved unauthorized access to payment card systems at food and beverage outlets from June 23 to July 7, 2016, exposing payment card data. Banner Health engaged forensic investigators, law enforcement, and Kroll for credit monitoring services.
- 🦫Oregon State AGas victim2016-08-03
Banner Health reported a data breach to the Oregon Attorney General. The breach was reported on 2016-08-03. The breach occurred during 6/17/2016 - 7/7/2016. The breach was discovered on 7/7/20167/13/2016. 3,623,140 individuals were affected. Notice was sent on 8/3/2016.
- FEDERALHHS OCRas victim2016-08-03
Banner Health reported to HHS on 2016-08-03 a Hacking/IT Incident affecting 3,620,000 individuals. An OCR investigation found pervasive noncompliance with the HIPAA Security Rule, leading to a $1,250,000 settlement and a corrective action plan. The breached information, located on a Network Server and other systems, included patient names, Social Security numbers, clinical details, and health insurance information.
- AZHHS OCRas victim2014-03-05
Banner Health (AZ) reported to HHS OCR on 2014-03-05 a breach classified as 'Other' affecting 55,207 individuals. The location of breached information is listed as 'Other'. No business associate was present. No further description is available from the HHS portal.