CITY OF HOPE
ent_019e0d8404165b63f4c430cab6f7c706
Disclosures
14
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
902,540
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CITY OF HOPE
- Normalized
- city of hope— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QIQJNNQEIXBL15
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cityofhope.org
Disclosure history (14)newest first
- Oregon State AGas victim2024-04-16
City of Hope reported a data breach to the Oregon Attorney General. The breach was reported on 2024-04-16. The breach occurred during 7/7/2023 - 10/15/2023. The breach was discovered on 3/25/2024. 827,149 individuals were affected. Notice was sent on 12/14/20234/2/2024.
- Massachusetts State AGas victim2024-04-03
City of Hope reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-04-03. 1,066 Massachusetts residents were affected.
- Oregon State AGas victim2024-04-03
City of Hope reported a data breach to the Oregon Attorney General. The breach was reported on 2024-04-03.
- New Hampshire State AGas victim2024-04-02
City of Hope, a cancer treatment and research organization, notified the New Hampshire Attorney General on April 2, 2024, of a data breach affecting approximately 181 NH residents. Unauthorized access occurred between September 19 and October 12, 2023. The incident involved the exfiltration of personal and health information, including names, medical record numbers, and potentially government IDs. City of Hope engaged forensic investigators, reported to law enforcement, and offered credit monitoring to affected individuals. The investigation was ongoing at the time of filing.
- Montana State AGas victim2024-04-02
City of Hope notified Montana residents of a data breach where unauthorized access occurred between September 19 and October 12, 2023. The incident exposed PHI, SSNs, financial data, and identity information. City of Hope engaged forensic investigators, reported to law enforcement, and provided two years of Kroll identity monitoring.
- Vermont State AGas victim2024-04-02
City of Hope notified Vermont AG of a data breach occurring between Sept 19 and Oct 12, 2023. Unauthorized third parties accessed systems and exfiltrated files containing PII, SSNs, financial data, and PHI. City of Hope engaged a cybersecurity firm, reported to law enforcement, and provided two years of Kroll identity monitoring to affected individuals.
- California State AGas victim2024-04-02
City of Hope disclosed that an unauthorized third party accessed its systems and copied files between September 19 and October 12, 2023. The organization became aware of suspicious activity on October 13, 2023. Affected data may include names, contact info, SSNs, government IDs, financial details, health insurance info, and medical records. City of Hope engaged a cybersecurity firm, implemented enhanced safeguards, notified law enforcement and regulators, and offered two years of identity monitoring via Kroll.
- Washington State AGas victim2024-04-02
City of Hope issued a supplemental notice to the Washington AG updating the affected Washington resident count to 3,784. The breach involved unauthorized access to systems between Sept 19 and Oct 12, 2023, discovered Oct 13, 2023. Data included PII, PHI, and financial info. Kroll identity monitoring offered.
- Maine State AGas victim2024-04-02
City of Hope, a healthcare entity based in Duarte, California, reported an external system breach (hacking) occurring between July 7, 2023, and October 15, 2023. The breach was discovered on March 25, 2024, and affected approximately 827,149 individuals, including 166 Maine residents. Personal information acquired included names and Social Security Numbers. City of Hope provided written notification and offered two years of complimentary identity theft monitoring through Kroll.
- Illinois State AGas victim2024-04-01
CITY OF HOPE filed a data-breach notice with the Illinois Attorney General in April 2024 (case 24-04-005). The register records the breach as discovered on October 13, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- CALIFORNIAHHS OCRas victim2023-12-12
City of Hope reported to HHS on 2023-12-12 a Hacking/IT Incident affecting 902,540 individuals. Breached information located on Network Server. The cyber-attack exposed PHI including names, DOB, SSN, driver's license, financial, and health insurance data. The entity notified HHS, individuals, and media, and implemented additional administrative, technical, and security safeguards.
- California State AGas victim2017-08-03
City of Hope experienced a phishing incident between May 31 and June 2, 2017, resulting in unauthorized access to four staff members' email accounts. Protected health information (PHI) including names, medical record numbers, and clinical data may have been accessed. The organization secured the accounts, engaged forensic investigators, and notified law enforcement. No evidence of data exfiltration or misuse was found.
- CALIFORNIAHHS OCRas victim2017-08-03
City of Hope reported to HHS on 2017-08-03 a Hacking/IT Incident affecting 3400 individuals. Breached information located on Email. A workforce member was victim of an email phishing scheme. PHI involved included names, addresses, DOB, SSN, diagnosis, lab results, medications, and treatment info. Remote VPN access was disabled.
- CALIFORNIAHHS OCRas victim2016-03-04
City of Hope reported to HHS on 2016-03-04 a Hacking/IT Incident affecting 1024 individuals. Breached information located on Email. The breach involved a phishing email containing an embedded link that granted unauthorized access to employee email accounts, exposing patient PHI including names, MRNs, DOBs, addresses, clinical data, and one SSN.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of CITY OF HOPE — not by CITY OF HOPE itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.