Torrance Memorial Medical Center
ent_1895b79d282219d3c3e20e59
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
46,632
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Torrance Memorial Medical Center
- Normalized
- torrance memorial medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🐻California State AGas victim2020-03-06
Torrance Memorial Medical Center notified patients of a data security incident involving an unsecured server used by an outside radiology vendor. The server was accessible from June 20, 2019, to December 13, 2019. Patient images and basic PII (name, DOB, MRN) were stored on the server, but no SSNs or financial data were involved. No evidence of unauthorized access to patient images was found. The vendor secured the server, and Torrance Memorial offered 12 months of identity monitoring services.
- 🦬Montana State AGas victim2017-07-07
Torrance Memorial Medical Center reported a data breach to the Montana Attorney General. The breach was reported on 2017-07-07. The breach occurred from 4/18/2016 to 4/19/2017. 5 Montana residents were affected.
- 🦬Montana State AGas victim2017-06-19
Torrance Memorial Medical Center reported a data breach to the Montana Attorney General. The breach was reported on 2017-06-19. The breach occurred from 4/18/2017 to 4/19/2017. 5 Montana residents were affected.
- CALIFORNIAHHS OCRas victim2017-06-19
HHS OCR breach portal entry: Torrance Memorial Medical Center (CA) reported a Hacking/IT Incident involving Email on 2017-06-19, affecting 46,632 individuals per the portal count (the narrative text states 44,960 individuals plus 3,304 SSNs — discrepancy noted). Two workforce members responded to a phishing email, exposing PHI including names, addresses, DOBs, healthcare claims information, diagnoses, medications, other treatment information, and 3,304 SSNs. The CE notified HHS, affected individuals, and the media; remediation included expanded security training, enhanced authentication, and improved malicious-email controls. OCR's investigation closed with the CE improving PHI safeguards.