MEMORIAL SLOAN-KETTERING CANCER CENTER
ent_019e0d7bccde9ec887ba7e3cd65f148e
Disclosures
6
HHS OCR · Leak Site · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
73,536
nationwide · HHS OCR NY
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MEMORIAL SLOAN-KETTERING CANCER CENTER
- Normalized
- memorial sloan kettering cancer center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300IZ71UAMEHWL382
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mskcc.org
Disclosure history (6)newest first
- NEW YORKHHS OCRas victim2024-06-25
Memorial Sloan Kettering Cancer Center reported to HHS on 2024-06-25 a Hacking/IT Incident (email phishing scheme) affecting 12,274 individuals. An employee was targeted via phishing, exposing PHI including names, addresses, dates of birth, diagnoses, lab results, medications, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and media, and implemented additional safeguards and staff retraining.
- GLOBALLeak Siteas victim2023-12-12
PREVIEW
- 🦬Montana State AGas victim2021-03-31
Memorial Sloan Kettering Cancer Center reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-31. The breach occurred from 1/20/2021 to 1/22/2021. 4 Montana residents were affected.
- NEW YORKHHS OCRas victim2020-09-14
Memorial Sloan Kettering Cancer Center reported to HHS on 2020-09-14 a Hacking/IT Incident affecting 73,536 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, emails, DOB, and phone numbers. CE notified HHS, individuals, and media.
- FEDERALHHS OCRas victim2013-11-13
Memorial Sloan-Kettering Cancer Center reported to HHS on 2013-11-13 a Loss affecting 2279 individuals. The breach was due to a former employee’s personal unencrypted external computer hard drive being lost or stolen. This drive contained patient information including names, addresses, dates of birth, and clinical information. The breached information was located on an Other Portable Electronic Device.
- FEDERALHHS OCRas victim2012-06-08
A staff member at Memorial Sloan-Kettering Cancer Center disclosed an unencrypted file containing the protected health information of 568 individuals to a non-covered entity physician, who subsequently re-disclosed it to a medical education organization for a presentation. The presentation was then posted on the organization's website. The exposed data included names, Social Security numbers, medical record numbers, and clinical information. In response, the center had the data removed, sanctioned the employee, and retrained its workforce. OCR's investigation confirmed the center implemented corrective actions.