BAYSTATE HEALTH, INC.
ent_019e10439b6fbe68e56df1a507a2f6a8
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
13,112
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BAYSTATE HEALTH, INC.
- Normalized
- baystate health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500DD69F547N03629
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🏛️Massachusetts State AGas reporting2026-07-01
Baystate Medical Center notified patients on July 15, 2026, regarding an error on June 12, 2026, where a patient's admission sheet containing name, DOB, and SSN was inadvertently sent to another patient. The information was retrieved, and affected individuals were offered two years of credit monitoring.
- 🏛️Massachusetts State AGas reporting2026-06-01
Baystate Noble Hospital, a subsidiary of Baystate Health, notified patients in Massachusetts of an insider incident on April 14, 2026. An employee took copies of out-of-state driver's licenses and health insurance cards off hospital property without legitimate business reason. The hospital retrieved the documents, took corrective action against the employee, and offered two years of Experian IdentityWorks credit monitoring to affected individuals. No clinical or treatment information was compromised.
- MASSACHUSETTSHHS OCRas victim2019-04-05
Baystate Health (MA) reported to HHS OCR on 2019-04-05 a Hacking/IT Incident affecting 11,658 individuals. Several employees were victims of an email phishing scheme that compromised ePHI including names, addresses, dates of birth, Social Security numbers, health insurance information, treatment information, and financial information. Breached information was located in Email. The CE notified HHS, individuals, and media; provided credit monitoring; and implemented additional safeguards and staff training. OCR obtained assurances of corrective actions.
- FEDERALHHS OCRas victim2016-10-21
Baystate Health, Inc. reported to HHS on October 21, 2016, a hacking incident that affected 13,112 individuals. The breach occurred on July 27, 2016, when five employees responded to a phishing email, allowing hackers to access their email accounts. The compromised information, located in the email accounts, potentially included patient names, demographic information, dates of birth, diagnoses, treatments, medical record numbers, and health insurance ID numbers. In response, the company retrained employees, issued phishing reminders, and improved technical safeguards.