BANNER HEALTH
ent_019e0d6c045dbf3afeebe8e6b8a946d6
Disclosures
10
HHS OCR enforcement · State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
3,700,000
nationwide · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BANNER HEALTH
- Normalized
- banner health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- PLD0E0WJKFN8IZJ2WD85
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bannerhealth.com
Disclosure history (10)newest first
- FEDERALHHS OCR enforcementas victim2021-01-12
HHS OCR settled its fourteenth enforcement action under the HIPAA Right of Access Initiative with Banner Health. The non-profit health system agreed to pay $200,000 and implement corrective actions to resolve potential violations of the HIPAA Privacy Rule's right of access standard.
- Washington State AGas victim2016-08-03
Banner Health disclosed a cyber attack initiated June 17, 2016, discovered July 7, 2016. Attackers accessed payment card data at food/beverage outlets and patient/provider server data including names, SSNs, and clinical info. ~3.7M individuals affected nationwide; 7,916 in WA. Notifications sent Aug 3, 2016. Credit monitoring offered.
- New Hampshire State AGas victim2016-08-03
Banner Health notified the New Hampshire Attorney General on August 3, 2016, regarding unauthorized access to patient servers occurring on June 17, 2016. The breach affected approximately 379 New Hampshire residents, exposing names, SSNs, health information, and financial data. Banner provided credit monitoring and established a call center.
- Montana State AGas victim2016-08-03
Banner Health disclosed a cyber attack affecting approximately 3.7 million individuals. Attackers gained unauthorized access to systems processing payment card data and patient/provider information between June 17 and July 7, 2016. Data exposed included names, SSNs, health info, and payment card details. Banner Health engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring via Kroll.
- Massachusetts State AGas victim2016-08-03
Banner Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-08-03. 1,041 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2016-08-03
Banner Health disclosed a cyber attack where attackers gained unauthorized access to patient, provider, and payment card data. The attack began on June 17, 2016, and was discovered in two phases: payment card systems on July 7, 2016, and patient/provider servers on July 13, 2016. Approximately 3.7 million individuals were affected. Data exposed included PHI, SSNs, and payment card details. Banner Health engaged forensics, blocked attackers, and offered credit monitoring.
- Oregon State AGas victim2016-08-03
Banner Health reported a data breach to the Oregon Attorney General. The breach was reported on 2016-08-03. The breach occurred during 6/17/2016 - 7/7/2016. The breach was discovered on 7/7/20167/13/2016. 3,623,140 individuals were affected. Notice was sent on 8/3/2016.
- ARIZONAHHS OCRas victim2016-08-03
Banner Health reported to HHS on 2016-08-03 a Hacking/IT Incident affecting 3,620,000 individuals. An OCR investigation found pervasive noncompliance with the HIPAA Security Rule, leading to a $1,250,000 settlement and a corrective action plan. The breached information, located on a Network Server and other systems, included patient names, Social Security numbers, clinical details, and health insurance information.
- Massachusetts State AGas victim2014-03-06
Banner Health Network reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-03-06. 2 Massachusetts residents were affected. The report records the breach type as paper.
- ARIZONAHHS OCRas victim2014-03-05
Banner Health (AZ) reported to HHS OCR on 2014-03-05 a breach classified as 'Other' affecting 55,207 individuals. The location of breached information is listed as 'Other'. No business associate was present. No further description is available from the HHS portal.