CITY OF HOPE
ent_019e0d8404165b63f4c430cab6f7c706
Disclosures
12
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
902,540
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CITY OF HOPE
- Normalized
- city of hope— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QIQJNNQEIXBL15
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cityofhope.org
Disclosure history (12)newest first
- 🦫Oregon State AGas victim2024-04-16
City of Hope reported a data breach to the Oregon Attorney General. The breach was reported on 2024-04-16. The breach occurred during 7/7/2023 - 10/15/2023. The breach was discovered on 3/25/2024. 827,149 individuals were affected. Notice was sent on 12/14/20234/2/2024.
- 🦫Oregon State AGas victim2024-04-03
City of Hope reported a data breach to the Oregon Attorney General. The breach was reported on 2024-04-03.
- ⛰️New Hampshire State AGas victim2024-04-02
City of Hope, a cancer treatment and research organization, notified the New Hampshire Attorney General on April 2, 2024, of a data breach affecting approximately 181 NH residents. Unauthorized access occurred between September 19 and October 12, 2023. The incident involved the exfiltration of personal and health information, including names, medical record numbers, and potentially government IDs. City of Hope engaged forensic investigators, reported to law enforcement, and offered credit monitoring to affected individuals. The investigation was ongoing at the time of filing.
- 🦬Montana State AGas victim2024-04-02
City of Hope reported a data breach to the Montana Attorney General. The breach was reported on 2024-04-02. The breach occurred on 10/13/2023. 580 Montana residents were affected.
- 🍁Vermont State AGas victim2024-04-02
City of Hope notified Vermont AG of a data breach occurring between Sept 19 and Oct 12, 2023. Unauthorized third parties accessed systems and exfiltrated files containing PII, SSNs, financial data, and PHI. City of Hope engaged a cybersecurity firm, reported to law enforcement, and provided two years of Kroll identity monitoring to affected individuals.
- 🐻California State AGas victim2024-04-02
City of Hope disclosed that an unauthorized third party accessed its systems and copied files between September 19 and October 12, 2023. The organization became aware of suspicious activity on October 13, 2023. Affected data may include names, contact info, SSNs, government IDs, financial details, health insurance info, and medical records. City of Hope engaged a cybersecurity firm, implemented enhanced safeguards, notified law enforcement and regulators, and offered two years of identity monitoring via Kroll.
- 🌲Washington State AGas victim2024-04-02
City of Hope, a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-10-13 and filed notice on 2024-04-02. 3,784 Washington residents were affected. 172 days elapsed between awareness and notification. 98 days to identify the breach. 2 days to contain the breach.
- 🦞Maine State AGas victim2024-04-02
City of Hope, a healthcare entity based in Duarte, California, reported an external system breach (hacking) occurring between July 7, 2023, and October 15, 2023. The breach was discovered on March 25, 2024, and affected approximately 827,149 individuals, including 166 Maine residents. Personal information acquired included names and Social Security Numbers. City of Hope provided written notification and offered two years of complimentary identity theft monitoring through Kroll.
- CALIFORNIAHHS OCRas victim2023-12-12
City of Hope reported to HHS on 2023-12-12 a Hacking/IT Incident affecting 902,540 individuals. Breached information located on Network Server. The cyber-attack exposed PHI including names, DOB, SSN, driver's license, financial, and health insurance data. The entity notified HHS, individuals, and media, and implemented additional administrative, technical, and security safeguards.
- 🐻California State AGas victim2017-08-03
City of Hope notified California regulators and patients of a phishing incident in May 2017. The attack compromised four staff email accounts containing patient PHI (names, MRNs, DOB, clinical info). No SSN or financial data was involved. City of Hope secured accounts, engaged forensic investigators, and reported to law enforcement.
- CALIFORNIAHHS OCRas victim2017-08-03
City of Hope reported to HHS on 2017-08-03 a Hacking/IT Incident affecting 3400 individuals. Breached information located on Email. A workforce member was victim of an email phishing scheme. PHI involved included names, addresses, DOB, SSN, diagnosis, lab results, medications, and treatment info. Remote VPN access was disabled.
- CALIFORNIAHHS OCRas victim2016-03-04
City of Hope reported to HHS on 2016-03-04 a Hacking/IT Incident affecting 1024 individuals. Breached information located on Email. The breach involved a phishing email containing an embedded link that granted unauthorized access to employee email accounts, exposing patient PHI including names, MRNs, DOBs, addresses, clinical data, and one SSN.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of CITY OF HOPE — not by CITY OF HOPE itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.