St. Francis Hospital, Inc.
ent_019e20a56dc9a005ef3a279a0678bd73
Disclosures
3
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,175
nationwide · HHS OCR GA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- St. Francis Hospital, Inc.
- Normalized
- st francis hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300WQRU63PQ7XAH83
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- Montana State AGas victim2022-08-12
Conifer Revenue Cycle Solutions, LLC notified St. Francis Hospital patients of a data breach where an unauthorized party accessed a Microsoft Office 365 business email account starting January 20, 2022. Conifer discovered the incident on April 14, 2022. The email contained patient PII, medical records, and billing information. Conifer reset passwords, blocked malicious IPs, and enhanced security controls.
- New Hampshire State AGas reporting2018-05-31
St. Mary's Health, Inc. d/b/a St. Vincent Evansville notified the NH Attorney General of a data incident affecting 4 New Hampshire residents. On February 12, 2018, the hospital detected unusual internet traffic accessing a server hosting credentialing software. Investigation revealed a server configuration error that exposed data to the internet. The server was taken offline and reconfigured. Forensic analysis indicated unauthorized access attempts from outside the US, but no evidence of data posting to the dark web was found. Affected data included names, addresses, dates of birth, phone numbers, driver's licenses, SSNs, and National Provider Data Bank reports. The hospital offered one year of identity theft monitoring.
- GEORGIAHHS OCRas victim2014-06-09
On May 30, 2014, a staff member at St. Francis Hospital sent an email to approximately 1,175 patients that erroneously permitted them to see the email addresses of all recipients. The hospital investigated the incident, replaced its IT department leadership and security officer, retrained the workforce, and began upgrading its equipment to prevent future incidents. OCR provided technical assistance.