Atrium Health Foundation
ent_1077c51e0a1c5c1fc9b92c97
Disclosures
11
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
585,959
nationwide · HHS OCR NC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Atrium Health Foundation
- Normalized
- atrium health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493005K55WBPVQWGU50
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- atriumhealth.org
Disclosure history (11)newest first
- NORTH CAROLINAHHS OCRas victim2024-12-02
Atrium Health reported to HHS on 2024-12-02 an Unauthorized Access/Disclosure affecting 585,959 individuals. The breach stemmed from historical use of web tracking technology on its patient portal, which may have exposed PHI including clinical and demographic information. Breached information was located on a Network Server. The CE notified HHS, affected individuals, the media, and posted substitute notice.
- Montana State AGas victim2024-09-13
Atrium Health notified affected individuals in Montana and other states that an unauthorized third party gained access to employee email accounts via phishing on April 29, 2024. The incident may have exposed personal, health, and financial information. Atrium Health engaged forensic consultants, notified law enforcement, secured accounts, and offered 24 months of Kroll identity monitoring.
- NORTH CAROLINAHHS OCRas victim2024-09-13
Atrium Health reported to HHS on 2024-09-13 a Hacking/IT Incident affecting 32120 individuals. Breached information located on Email.
- Illinois State AGas victim2024-09-01
ATRIUM HEALTH filed a data-breach notice with the Illinois Attorney General in September 2024 (case 24-09-046). The register records the breach as discovered on April 29, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NORTH CAROLINAHHS OCRas reporting2022-06-07
Atrium Health at Home reported to HHS on 2022-06-07 a Hacking/IT Incident affecting 6,695 individuals. Breached information located on Email. An employee was the subject of an email phishing scheme that exposed PHI including names, DOB, addresses, SSNs, medications, and diagnoses. Response included credit monitoring, security safeguards, and staff retraining.
- Montana State AGas victim2020-09-01
Atrium Health notified Montana residents of a third-party vendor breach involving Blackbaud. A ransomware attack on Blackbaud's systems (Feb-May 2020) led to the exfiltration of patient personal and demographic data. Atrium Health investigated, set up a call center, and is reviewing security safeguards.
- NORTH CAROLINAHHS OCRas victim2020-09-01
Atrium Health (NC) reported to HHS on 2020-09-01 a Hacking/IT Incident (ransomware) affecting 165,000 individuals. The breach occurred at a business associate and involved ePHI stored on a network server. Exposed data included names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website.
- New Hampshire State AGas victim2018-11-27
Atrium Health notified NH AG of a breach at third-party vendor AccuDoc Solutions. Unauthorized access occurred Sept 22-29, 2018. Data involved: names, addresses, DOB, SSNs, medical record numbers, insurance info. 586 total individuals affected (64 NH residents). Notifications sent Nov 27, 2018. Forensic investigators engaged; FBI notified; credit monitoring offered.
- Montana State AGas victim2018-11-27
Atrium Health notified patients of a cyber incident involving third-party billing vendor AccuDoc Solutions. Unauthorized access to AccuDoc's databases occurred between Sept 22-29, 2018. Data potentially exposed included names, addresses, DOB, insurance info, medical record numbers, and SSNs. Atrium engaged forensic investigators and FBI; offered 1-year Kroll identity monitoring.
- South Carolina State AGas victim2018-11-27
Atrium Health notified patients of a cyber incident involving third-party billing vendor AccuDoc Solutions, Inc. Unauthorized access to AccuDoc's databases occurred between Sept 22-29, 2018. Patient PII including names, addresses, DOBs, SSNs, and medical record numbers were potentially exposed. No financial account numbers or clinical records were accessed. Atrium engaged forensic investigators and offered one year of free credit monitoring.
- Massachusetts State AGas victim2018-11-27
Atrium Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-11-27. 257 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- Atrium Health Foundation’s filing is one of at least 4 in the AccuDoc Solutions, Inc. supply-chain incident (2018).