MEMORIAL SLOAN-KETTERING CANCER CENTER
ent_019e0d7bccde9ec887ba7e3cd65f148e
Disclosures
9
HHS OCR · State AG · Leak Site · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
73,536
nationwide · HHS OCR NY
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MEMORIAL SLOAN-KETTERING CANCER CENTER
- Normalized
- memorial sloan kettering cancer center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300IZ71UAMEHWL382
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mskcc.org
Disclosure history (9)newest first
- NEW YORKHHS OCRas victim2024-06-25
Memorial Sloan Kettering Cancer Center reported to HHS on 2024-06-25 a Hacking/IT Incident (email phishing scheme) affecting 12,274 individuals. An employee was targeted via phishing, exposing PHI including names, addresses, dates of birth, diagnoses, lab results, medications, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and media, and implemented additional safeguards and staff retraining.
- Illinois State AGas victim2024-06-01
MEMORIAL SLOAN KETTERING CANCER CENTER filed a data-breach notice with the Illinois Attorney General in June 2024 (case 24-06-047). The register records the breach as discovered on April 22, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2023-12-12
PREVIEW
- Montana State AGas victim2021-03-31
Memorial Sloan Kettering Cancer Center (MSK) notified patients of a breach involving its Accellion FileBridge document-sharing system. Unauthorized access occurred Jan 20-22, 2021. Data accessed included names, addresses, DOBs, and PHI. No SSNs or financial data were compromised. MSK took the system offline permanently and engaged IDX for support.
- NEW YORKHHS OCRas victim2021-03-31
Memorial Sloan Kettering Cancer Center reported to HHS on 2021-03-31 a Unauthorized Access/Disclosure affecting 18913 individuals. Breached information located on Network Server. Business associate employees misconfigured a server exposing PHI including names, SSNs, DOBs, addresses, financial info, diagnoses, and treatment data.
- NEW YORKHHS OCRas victim2020-09-14
Memorial Sloan Kettering Cancer Center reported to HHS on 2020-09-14 a Hacking/IT Incident affecting 73,536 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, emails, DOB, and phone numbers. CE notified HHS, individuals, and media.
- Illinois State AGas victim2020-01-01
MEMORIAL SLOAN KETTERING CANCER CENTER filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-364). The register records the breach as discovered on May 14, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NEW YORKHHS OCRas victim2013-11-13
Memorial Sloan-Kettering Cancer Center reported to HHS on 2013-11-13 a Loss affecting 2279 individuals. The breach was due to a former employee’s personal unencrypted external computer hard drive being lost or stolen. This drive contained patient information including names, addresses, dates of birth, and clinical information. The breached information was located on an Other Portable Electronic Device.
- NEW YORKHHS OCRas victim2012-06-08
A staff member at Memorial Sloan-Kettering Cancer Center disclosed an unencrypted file containing the protected health information of 568 individuals to a non-covered entity physician, who subsequently re-disclosed it to a medical education organization for a presentation. The presentation was then posted on the organization's website. The exposed data included names, Social Security numbers, medical record numbers, and clinical information. In response, the center had the data removed, sanctioned the employee, and retrained its workforce. OCR's investigation confirmed the center implemented corrective actions.