BAYSTATE HEALTH, INC.
ent_019e10439b6fbe68e56df1a507a2f6a8
Disclosures
8
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
13,112
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BAYSTATE HEALTH, INC.
- Normalized
- baystate health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500DD69F547N03629
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- New Hampshire State AGas victim2019-04-08
Baystate Health notified the NH Attorney General of a phishing incident between Feb 7 and Mar 7, 2019, resulting in unauthorized access to employee email accounts. One New Hampshire resident's PHI, including name, address, DOB, SSN, Medicare number, and health information, was potentially exposed. Baystate secured accounts, engaged forensics, and offered credit monitoring.
- MASSACHUSETTSHHS OCRas victim2019-04-05
Baystate Health (MA) reported to HHS OCR on 2019-04-05 a Hacking/IT Incident affecting 11,658 individuals. Several employees were victims of an email phishing scheme that compromised ePHI including names, addresses, dates of birth, Social Security numbers, health insurance information, treatment information, and financial information. Breached information was located in Email. The CE notified HHS, individuals, and media; provided credit monitoring; and implemented additional safeguards and staff training. OCR obtained assurances of corrective actions.
- Illinois State AGas victim2019-01-01
BAYSTATE HEALTH filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-177). The register records the breach as discovered on February 7, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2017-04-12
Baystate Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-04-12. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2016-10-24
Baystate Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-10-24. 21 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2016-10-21
Baystate Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-10-21. 21 Massachusetts residents were affected. The report records the breach type as electronic.
- MASSACHUSETTSHHS OCRas victim2016-10-21
Baystate Health, Inc. reported to HHS on October 21, 2016, a hacking incident that affected 13,112 individuals. The breach occurred on July 27, 2016, when five employees responded to a phishing email, allowing hackers to access their email accounts. The compromised information, located in the email accounts, potentially included patient names, demographic information, dates of birth, diagnoses, treatments, medical record numbers, and health insurance ID numbers. In response, the company retrained employees, issued phishing reminders, and improved technical safeguards.
- Massachusetts State AGas victim2015-02-26
Baystate Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-02-26. 4 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of BAYSTATE HEALTH, INC. — not by BAYSTATE HEALTH, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia Baystate Noble Hospital2026-06-11
Baystate Noble Hospital, a subsidiary of Baystate Health, notified patients in Massachusetts of an insider incident on April 14, 2026. An employee took copies of out-of-state driver's licenses and health insurance cards off hospital property without legitimate business reason. The hospital retrieved the documents, took corrective action against the employee, and offered two years of Experian IdentityWorks credit monitoring to affected individuals. No clinical or treatment information was compromised.
- Massachusetts State AGvia Baystate Noble Hospital2026-02-19
Baystate Franklin Medical Center notified a patient that their paperwork, including an Authorization of Temporary Involuntary Hospitalization form containing name, address, DOB, MRN, SSN, and mental health treatment details, was inadvertently co-mingled with another patient's discharge paperwork on a mixed-use printer/fax machine on January 13, 2026. The error was discovered on January 15, 2026. The recipient reported the incident and shredded the documents. The organization provided staff re-education and is working with IT on printing workflows. Complimentary identity monitoring was offered.
- Massachusetts State AGvia Baystate Noble Hospital2023-07-07
Baystate Health Noble Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-07. 1 Massachusetts residents were affected. The report records the breach type as paper.