INTEGRIS Health
ent_0835038703e1b7feaca249cd
Disclosures
12
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,385,646
nationwide · HHS OCR OK
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INTEGRIS Health
- Normalized
- integris health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- integrisandme.com
Disclosure history (12)newest first
- New Hampshire State AGas victim2024-03-26
INTEGRIS Health notified one New Hampshire resident of a data breach involving IH Community Hospitals. An unauthorized party accessed a file containing patient information on November 28, 2023. The incident was discovered later, with forensic review concluding in January 2024. INTEGRIS Health engaged third-party specialists, secured systems, and is offering 24 months of credit monitoring. The incident is contained.
- California State AGas victim2024-03-26
INTEGRIS Health, operating on behalf of INTEGRIS Health Community Hospitals in Oklahoma, notified patients of unauthorized access to a file on or about November 28, 2023 by an unknown external party. Affected data included names, dates of birth, demographic and admission/discharge information, medical record numbers, and/or Social Security numbers. INTEGRIS Health engaged cybersecurity specialists, implemented security enhancements, and offered 24 months of complimentary identity protection through IDX.
- New Hampshire State AGas victim2024-03-01
INTEGRIS Health, Inc. notified the NH Attorney General of unauthorized access to certain systems on November 28, 2023. The investigation determined that files containing patient personal information were accessed by an unauthorized party. On December 24, 2023, patients began receiving communications from a group claiming responsibility. INTEGRIS Health engaged third-party cybersecurity specialists, secured the environment, and is offering credit monitoring and identity theft protection services through IDX to affected individuals. The incident involved PHI and PII of patients in multiple states including NH, RI, NY, NC, NM, MD, and DC.
- California State AGas victim2024-03-01
INTEGRIS Health discovered unauthorized access to certain systems, with files potentially accessed and/or acquired on November 28, 2023. A group later claimed responsibility. Affected data included names and personal information. A supplemental notice was sent to impacted individuals on March 1, 2024, offering 24 months of free IDX credit monitoring. Approximately 100 Rhode Island residents were noted as potentially impacted.
- Montana State AGas victim2024-03-01
Integris Health, Inc. notified individuals of unauthorized access to patient files on November 28, 2023. The incident involved potential access to names and other personal information. A group claiming responsibility contacted patients on December 24, 2023. Integris Health engaged third-party cybersecurity specialists and is offering 24 months of credit monitoring. No financial or driver's license data was involved.
- California State AGas victim2024-02-06
INTEGRIS Health notified California residents of unauthorized access to certain systems on November 28, 2023. An unauthorized party accessed and/or acquired files containing personal information including names and other data elements (excluding employment, driver's license, financial/payment, or credentials). A group claimed responsibility in December 2023. INTEGRIS engaged third-party cybersecurity specialists, reviewed affected data, and is offering 24 months of IDX credit monitoring. Approximately 95 Rhode Island residents were noted as impacted.
- New Hampshire State AGas victim2024-02-06
INTEGRIS Health, Inc. notified the NH Attorney General of an incident where an unauthorized party accessed files on November 28, 2023. The investigation determined that patient information, including names, Social Security numbers, dates of birth, and potentially financial information, was accessed or acquired. The organization engaged third-party cybersecurity specialists, notified law enforcement and HHS, and is offering credit monitoring to affected individuals. The incident is contained.
- Washington State AGas victim2024-02-06
INTEGRIS Health, Inc. filed a supplemental notice with the Washington AG regarding a cyberattack affecting INTEGRIS Health Community Hospitals. Unauthorized access occurred on November 28, 2023, exposing patient names, SSNs, DOBs, and medical records. 2,025 Washington residents were notified. The incident is contained; credit monitoring is offered.
- Massachusetts State AGas victim2024-02-06
INTEGRIS Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-06. 547 Massachusetts residents were affected.
- Illinois State AGas victim2024-02-01
INTEGRIS HEALTH, INC filed a data-breach notice with the Illinois Attorney General in February 2024 (case 24-02-035). The register records the breach as discovered on November 27, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OKLAHOMAHHS OCRas victim2024-01-26
INTEGRIS Health reported to HHS on 2024-01-26 a Hacking/IT Incident affecting 2385646 individuals. Breached information located on Network Server.
- OKLAHOMAHHS OCRas victim2019-12-16
INTEGRIS Health, Inc. reported to HHS on 2019-12-16 a Loss affecting 1,245,218 individuals. Breached information located on Other Portable Electronic Device. Two portable hard drives containing ePHI (names, diagnoses, clinical/treatment info) were missing. The responsible workforce member was sanctioned and safeguards were implemented.