Baptist Health
ent_019e0d6dc2cc090a828867e85b8e5ffc
Disclosures
6
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
16,765
nationwide · HHS OCR AR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Baptist Health
- Normalized
- baptist health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300C8SQLJKAFU3E59
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- New Hampshire State AGas victim2024-10-02
Baptist Health notified the NH Attorney General of a security incident at Baptist Health Medical Center-Drew County. Unauthorized access occurred between April 22 and July 8, 2024, affecting employee and dependent PII. Baptist Health became aware on July 8, 2024, engaged forensic investigators, notified law enforcement, and mailed notifications to 1 NH resident on Sept 30, 2024, offering Experian IdentityWorks.
- Indiana State AGas victim2024-09-30
Baptist Health reported a data breach to the Indiana Attorney General. The breach occurred on 2024-04-22 and was reported on 2024-09-30. 1 Indiana residents were affected. 1,823 individuals affected in total.
- ARKANSASHHS OCRas victim2021-04-21
Baptist Health Arkansas reported to HHS on 2021-04-21 a Hacking/IT Incident affecting 16,765 individuals. Breached information located on Network Server. A business associate experienced a cyber-attack affecting ePHI including names and treatment information. The covered entity terminated its business relationship with the business associate.
- ARKANSASHHS OCRas victim2018-05-07
Baptist Health (AR) reported to HHS OCR on 2018-05-07 an Unauthorized Access/Disclosure affecting 3,453 individuals. A physician stored patient PHI — including names, dates of birth, and treatment information — on a cloud-based file-sharing application without a Business Associate contract. Breached information was located on a Network Server/cloud storage. CE notified HHS, affected individuals, and media; subsequently improved safeguards, updated policies, and trained EHR users. OCR obtained corrective-action assurances.
- TEXASHHS OCRas victim2013-01-22
Baptist Health System reported to HHS on 2013-01-22 a Unauthorized Access/Disclosure affecting 678 individuals. Breached information located on Electronic Medical Record.
- ALABAMAHHS OCRas victim2012-05-04
Baptist Health System reported to HHS on 2012-05-04 a Improper Disposal affecting 1655 individuals. Breached information located on Paper/Films. A trash bag containing discarded appointment schedules was inadvertently removed from a shred bin by a cleaning service and disposed of in a dumpster without being shredded.