OVERLAKE MEDICAL CENTER & CLINICS
ent_019e1019cf186f98bab57267a5545ceb
Disclosures
7
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
109,234
nationwide · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- OVERLAKE MEDICAL CENTER & CLINICS
- Normalized
- overlake medical center clinics— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930008PFGREGKO6H92
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Washington State AGas victim2022-08-12
Overlake Medical Center & Clinics notified Washington AG of unauthorized access to a staff member's email account between June 13-14, 2022. The attacker obtained login credentials. Data accessed included names, DOBs, medical record numbers, and billing info for 519 WA residents. No SSNs or financial account numbers were involved. Notifications sent August 12, 2022.
- WASHINGTONHHS OCRas victim2022-08-12
Overlake Medical Center & Clinics reported to HHS on 2022-08-12 a Hacking/IT Incident affecting 557 individuals. Breached information located on Network Server. An employee was the subject of an email phishing attack that compromised PHI including names, addresses, birthdates, diagnoses, and health insurance information.
- WASHINGTONHHS OCRas victim2020-02-07
Overlake Medical Center & Clinics reported to HHS on 2020-02-07 a Hacking/IT Incident affecting 109,234 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing ePHI including names, health insurance, clinical info, and diagnoses.
- Montana State AGas victim2020-02-07
Overlake Medical Center & Clinics notified Montana AG of a phishing incident where attackers stole credentials for one email account on Dec 6, 2019. Attackers accessed the account through Dec 9, 2019, potentially exposing patient PII and PHI. Overlake secured accounts, reset passwords, and implemented MFA.
- California State AGas victim2020-02-07
Overlake Medical Center & Clinics experienced a phishing incident where attackers used deceptive emails to obtain employee login credentials. Unauthorized access to email accounts occurred between December 6-9, 2019, potentially exposing demographic, health insurance, and clinical information for 1,087 California residents. The organization secured accounts, engaged forensic investigators, and implemented MFA and enhanced security training.
- Oregon State AGas victim2020-02-07
Overlake Medical Center & Clinics reported a data breach to the Oregon Attorney General. The breach was reported on 2020-02-07. The breach occurred during 12/6/2019 - 12/9/2019. The breach was discovered on 12/9/2019. 109,000 individuals were affected. Notice was sent on 2/4/2020.
- Illinois State AGas victim2020-01-01
OVERLAKE MEDICAL CENTER & CLINICS filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-046). The register records the breach as discovered on December 11, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.