HOSPITAL SISTERS HEALTH SYSTEM
ent_019e1fc2943263df0a95ee9773079e0e
Disclosures
19
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
882,782
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HOSPITAL SISTERS HEALTH SYSTEM
- Normalized
- hospital sisters health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493003FCOY2H48ASF97
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (19)newest first
- Illinois State AGas victim2026-01-01
HOSPITAL SISTERS HEALTH SYSTEM filed a data-breach notice with the Illinois Attorney General in January 2026 (case 26-01-784). The register records the breach as discovered on April 15, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2025-02-07
Hospital Sisters Health System (HSHS) filed a supplemental notice with the New Hampshire Attorney General regarding a data security incident. HSHS discovered unauthorized third-party access to its network on August 27, 2023. The attacker accessed files between August 16 and August 27, 2023. The incident affected 41 New Hampshire residents, whose personal information (including SSNs and medical IDs) was accessed. HSHS engaged forensic investigators, notified law enforcement, and offered credit monitoring services.
- California State AGas victim2025-02-06
Hospital Sisters Health Systems (HSHS) discovered on August 27, 2023, that an unauthorized third party gained temporary access to its network between August 16 and August 27, 2023. The incident potentially exposed personal information including names, addresses, dates of birth, medical record numbers, limited treatment information, health insurance information, Social Security numbers, and driver's license numbers. HSHS contained the incident, engaged forensic investigators, and is offering one year of credit monitoring to affected individuals.
- Washington State AGas victim2025-02-06
Hospital Sisters Health System (HSHS) notified the Washington AG of a breach affecting 662 WA residents. Unauthorized access occurred Aug 16-27, 2023. Data included names, SSNs, driver's licenses, PHI. HSHS engaged forensic investigators, notified law enforcement, and offered credit monitoring.
- Maine State AGas victim2025-02-06
Hospital Sisters Health System (HSHS) disclosed an external system breach (hacking) occurring between August 16 and August 27, 2023, discovered on August 27, 2023. The incident affected 882,782 individuals, including 79 Maine residents. Compromised data included names, addresses, DOBs, medical record numbers, limited treatment info, health insurance info, SSNs, and driver's license numbers. HSHS engaged forensic investigators, notified law enforcement, and offered 12 months of Equifax Credit Watch Gold. Notification was sent on August 30, 2024.
- Indiana State AGas victim2024-08-30
Hospital Sisters Health System reported a data breach to the Indiana Attorney General. The breach occurred on 2023-08-16 and was reported on 2024-08-30. 28 Indiana residents were affected. 240,893 individuals affected in total.
- Massachusetts State AGas victim2024-08-30
Hospital Sisters Health System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-30. 146 Massachusetts residents were affected.
- Montana State AGas victim2024-08-30
Hospital Sisters Health System (HSHS) notified Montana residents of a cybersecurity incident discovered on August 27, 2023. An unauthorized third party gained temporary access to HSHS's network between August 16 and August 27, 2023. The incident potentially exposed personal information including names, addresses, dates of birth, Social Security numbers, and/or driver's license numbers. HSHS engaged forensic investigators, reported the incident to law enforcement, and enhanced technical security measures. Affected individuals were offered a one-year Experian IdentityWorks membership.
- Illinois State AGas victim2024-08-01
HOSPITAL SISTERS HEALTH SYSTEM filed a data-breach notice with the Illinois Attorney General in August 2024 (case 24-08-068). The register records the breach as discovered on August 16, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- ILLINOISHHS OCRas victim2023-10-26
Hospital Sisters Health System reported to HHS on 2023-10-26 a Hacking/IT Incident affecting 500 individuals. Breached information located on Network Server. PHI included names, DOB, SSNs, claims, and treatment info. BA implemented additional safeguards; OCR provided assistance.
- Illinois State AGas victim2023-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS MEDICAL GROUP, INC.) filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-849). The register records the breach as discovered on November 6, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS MEDICAL GROUP, INC.) filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-001). The register records the breach as discovered on January 23, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS MEDICAL GROUP, INC.) filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-850). The register records the breach as discovered on November 8, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS MEDICAL GROUP, INC.) filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-757). The register records the breach as discovered on August 16, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS MEDICAL GROUP, INC.) filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-848). The register records the breach as discovered on November 1, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS) filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-013). The register records the breach as discovered on July 19, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
HOSPITAL SISTERS HEALTH SYSTEM (HSHS) filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-014). The register records the breach as discovered on January 4, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- ILLINOISHHS OCRas victim2020-01-31
Hospital Sisters Health System reported to HHS on 2020-01-31 a Hacking/IT Incident affecting 16,167 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme exposing PHI including names, SSNs, addresses, DOB, diagnoses, and medications. Response included credit monitoring, security safeguards, and staff retraining.
- Illinois State AGas victim2020-01-01
HOSPIAL SISTES HEALTH SYSTEM filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-041). The register records the breach as discovered on March 13, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (5)filed by group companies
◈ These filings were made by or about subsidiaries of HOSPITAL SISTERS HEALTH SYSTEM — not by HOSPITAL SISTERS HEALTH SYSTEM itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Illinois State AGvia HOSPITAL SISTERS SERVICES, INC.2023-01-01
HOSPITAL SISTERS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-418). The register records the breach as discovered on May 10, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia HOSPITAL SISTERS SERVICES, INC.2023-01-01
HOSPITAL SISTERS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-420). The register records the breach as discovered on June 7, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia HOSPITAL SISTERS SERVICES, INC.2023-01-01
HOSPITAL SISTERS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-419). The register records the breach as discovered on May 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia HOSPITAL SISTERS SERVICES, INC.2023-01-01
HOSPITAL SISTERS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-416). The register records the breach as discovered on May 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia HOSPITAL SISTERS SERVICES, INC.2023-01-01
HOSPITAL SISTERS filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-650). The register records the breach as discovered on July 28, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.