Cummins Behavioral Health Systems, Inc.
ent_019e209c6cfac57a5a038bfda71f7376
Disclosures
6
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
157,688
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cummins Behavioral Health Systems, Inc.
- Normalized
- cummins behavioral health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930094IWVFCB6QNY62
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- New Hampshire State AGas victim2023-08-18
Cummins Behavioral Health Systems, Inc. reported a ransomware incident to the New Hampshire Attorney General. Unauthorized activity occurred between Feb 2 and Mar 9, 2023. The company discovered a ransom note on Mar 9, 2023, but no data was encrypted. Personal information of 3 NH residents was potentially impacted. Notifications were mailed on Aug 1, 2023, offering credit monitoring.
- Massachusetts State AGas victim2023-08-11
Cummins Behavioral Health Systems, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-11. 10 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-08-11
Cummins Behavioral Health reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-02 and was reported on 2023-08-11. 103,591 Indiana residents were affected. 157,688 individuals affected in total.
- Maine State AGas victim2023-08-11
Cummins Behavioral Health Systems, Inc. reported a data breach affecting 8 Maine residents. The breach, which occurred on February 2, 2023, and was discovered on March 9, 2023, was described as an external system breach or hacking. The compromised information included names and Social Security numbers. Affected individuals were notified on August 11, 2023, and offered identity theft protection services through TransUnion.
- Montana State AGas victim2023-08-11
Cummins Behavioral Health Systems, Inc. notified individuals of a ransomware incident discovered on March 9, 2023. The incident occurred between Feb 2 and March 9, 2023. A ransom note was found, but no files were encrypted. Personal information and PHI may have been accessed. The company engaged a cybersecurity firm and offered credit monitoring.
- INDIANAHHS OCRas victim2023-04-12
Cummins Behavioral Health Systems reported to HHS on 2023-04-12 a ransomware attack affecting 154,285 individuals. The breach involved protected health information (PHI), including Social Security numbers and detailed medical data, located on a network server. In response, the entity implemented additional safeguards, and OCR provided technical assistance.