BETH ISRAEL LAHEY HEALTH, INC.
ent_019fade67aedd7d47673ef99fcca6190
Disclosures
3
State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
3
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BETH ISRAEL LAHEY HEALTH, INC.
- Normalized
- beth israel lahey health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QPZ5W3279DU141
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- New Hampshire State AGas reporting2023-09-21
Ricoh USA, Inc. notified the NH Attorney General of a security incident involving 3 New Hampshire residents. On May 31, 2023, Progress Software Corporation notified customers of a zero-day vulnerability in the MOVEit managed file transfer platform. An unauthorized party exploited this vulnerability to access and acquire data from Ricoh's MOVEit instance. The compromised data may have included names, addresses, Social Security numbers, and financial account information. Ricoh secured its instance, conducted an investigation, and is offering credit monitoring to affected individuals.
- Massachusetts State AGas victim2019-03-22
Lahey Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-22. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2019-02-07
Lahey Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-02-07. 2 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- BETH ISRAEL LAHEY HEALTH, INC.’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of BETH ISRAEL LAHEY HEALTH, INC. — not by BETH ISRAEL LAHEY HEALTH, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia BETH ISRAEL DEACONESS MEDICAL CENTER, INC.2026-01-21
Beth Israel Deaconess Medical Center (BIDMC) notified a patient that a research study form containing their full Social Security number and protected health information was inadvertently disclosed to another patient on December 19, 2025. The incident was caused by an employee error. BIDMC counseled the employee and offered 24 months of identity monitoring services.
- New Hampshire State AGvia ANNA JAQUES HOSPITAL2024-12-10
Anna Jaques Hospital notified NH AG of a cybersecurity incident occurring Dec 25, 2023. Unauthorized access to files containing PHI and PII of 15,327 NH residents was discovered Nov 5, 2024. Response included containment, law enforcement alert, forensic investigation, password resets, and credit monitoring offers.
- Massachusetts State AGvia ANNA JAQUES HOSPITAL2024-12-05
Anna Jaques Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-12-05. 81,268 Massachusetts residents were affected.
- Indiana State AGvia ANNA JAQUES HOSPITAL2024-12-05
Anna Jaques Hospital reported a data breach to the Indiana Attorney General. The breach occurred on 2023-11-17 and was reported on 2024-12-05. 13 Indiana residents were affected. 316,342 individuals affected in total.
- Vermont State AGvia ANNA JAQUES HOSPITAL2024-12-05
Anna Jaques Hospital notified consumers of a data breach involving unauthorized access to patient and employee records. Compromised data included names, SSNs, dates of birth, driver's license numbers, and financial account numbers. The hospital reset passwords, updated security policies, and offered 24 months of credit monitoring via Experian IdentityWorks.
- Maine State AGvia ANNA JAQUES HOSPITAL2024-12-05
Anna Jaques Hospital reported an external system breach (hacking) affecting 316,342 individuals, including 637 Maine residents. The breach occurred on December 25, 2023, and was discovered on December 22, 2023. Notification was sent on December 5, 2024. Affected data included names, government IDs, and health/financial info. Remediation included password resets and policy updates.
- Massachusetts State AGvia WINCHESTER HOSPITAL2024-03-19
Winchester Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-03-19. 1 Massachusetts residents were affected.
- MASSACHUSETTSHHS OCRvia ANNA JAQUES HOSPITAL2024-02-20
Anna Jaques Hospital (a member of Beth Israel Health Incorporated) reported a hacking/IT incident affecting a network server and the PHI of 308,829 individuals. Compromised data included names, addresses, dates of birth, driver's license numbers, Social Security numbers, diagnoses, claims and financial information, medications, and other treatment information. The hospital notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards. No business associate was reported as involved.
- GLOBALLeak Sitevia ANNA JAQUES HOSPITAL2024-01-19
- GLOBALPressvia ANNA JAQUES HOSPITAL2023-12-25
Anna Jaques systems compromised after cyber issue | Local News | newburyportnews.com. Anna Jaques Hospital: Anna Jaques Hospital suffered a serious cyber incident that compromised its computer systems, causing delays in services and diverting ambulances to other hospitals on Christmas Day. Hospital administrators secured the environment and engaged cybersecurity professionals for the investigation, but did not provide details on the nature or target of the attack. The ambulance service resumed on December 26, and the hospital is working in collaboration with other facilities in the Beth Israel Lahey Health system. Linked ransomware group: moneymessage.