INTEGRIS Health
ent_0835038703e1b7feaca249cd
Disclosures
9
State AG · HHS OCR · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,245,218
nationwide · HHS OCR OK
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INTEGRIS Health
- Normalized
- integris health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- integrisandme.com
Disclosure history (9)newest first
- ⛰️New Hampshire State AGas victim2024-03-26
INTEGRIS Health, a healthcare provider and EHR support vendor, reported a supplemental breach affecting patients of IH Community Hospitals. Unauthorized access occurred on or about Nov 28, 2023, involving patient names and basic PII. The incident was contained, and IDX credit monitoring was offered. The filing is a supplemental notice to prior notifications.
- 🐻California State AGas victim2024-03-26
INTEGRIS Health, operating on behalf of INTEGRIS Health Community Hospitals in Oklahoma, notified patients of unauthorized access to a file on or about November 28, 2023 by an unknown external party. Affected data included names, dates of birth, demographic and admission/discharge information, medical record numbers, and/or Social Security numbers. INTEGRIS Health engaged cybersecurity specialists, implemented security enhancements, and offered 24 months of complimentary identity protection through IDX.
- ⛰️New Hampshire State AGas victim2024-03-01
INTEGRIS Health, Inc. notified New Hampshire AG of unauthorized access to patient systems on November 28, 2023. The breach involved potential theft of PII and government IDs. The company engaged third-party cybersecurity specialists, assessed systems, and is offering credit monitoring services to affected individuals.
- 🐻California State AGas victim2024-03-01
INTEGRIS Health discovered unauthorized access to certain systems, with files potentially accessed and/or acquired on November 28, 2023. A group later claimed responsibility. Affected data included names and personal information. A supplemental notice was sent to impacted individuals on March 1, 2024, offering 24 months of free IDX credit monitoring. Approximately 100 Rhode Island residents were noted as potentially impacted.
- 🦬Montana State AGas victim2024-03-01
Integris Health, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2024-03-01. The breach occurred on 11/28/2023. 5 Montana residents were affected.
- 🐻California State AGas victim2024-02-06
INTEGRIS Health notified California residents of unauthorized access to certain systems on November 28, 2023. An unauthorized party accessed and/or acquired files containing personal information including names and other data elements (excluding employment, driver's license, financial/payment, or credentials). A group claimed responsibility in December 2023. INTEGRIS engaged third-party cybersecurity specialists, reviewed affected data, and is offering 24 months of IDX credit monitoring. Approximately 95 Rhode Island residents were noted as impacted.
- ⛰️New Hampshire State AGas victim2024-02-06
INTEGRIS Health, Inc. notified New Hampshire AG of unauthorized access to patient files on November 28, 2023. The incident involved potential access to names and health information. INTEGRIS Health engaged third-party cybersecurity specialists, notified law enforcement, and is offering credit monitoring. A group claimed responsibility on December 24, 2023. Approximately 95 Rhode Island residents were impacted.
- 🌲Washington State AGas victim2024-02-06
INTEGRIS Health, a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-11-28 and filed notice on 2024-02-06. 2,120 Washington residents were affected. 70 days elapsed between awareness and notification. 1 days to identify the breach. 0 days to contain the breach.
- OKHHS OCRas victim2019-12-16
INTEGRIS Health, Inc. reported to HHS on 2019-12-16 a Loss affecting 1,245,218 individuals. Breached information located on Other Portable Electronic Device. Two portable hard drives containing ePHI (names, diagnoses, clinical/treatment info) were missing. The responsible workforce member was sanctioned and safeguards were implemented.