Torrance Memorial Medical Center
ent_1895b79d282219d3c3e20e59
Disclosures
9
HHS OCR · State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
46,632
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Torrance Memorial Medical Center
- Normalized
- torrance memorial medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- CALIFORNIAHHS OCRas victim2020-03-06
Torrance Memorial Medical Center reported to HHS on 2020-03-06 a Hacking/IT Incident affecting 3498 individuals. Breached information located on Network Server. A business associate was the victim of a cyber-attack affecting ePHI including clinical information, diagnoses, and treatment data.
- California State AGas victim2020-03-06
Torrance Memorial Medical Center notified patients that an outside radiology vendor's server was unsecured from June 20, 2019, to December 13, 2019. The server temporarily stored patient images containing names, dates of birth, gender, medical record numbers, and referring physician information. Torrance Memorial was notified of the issue on January 6, 2020. The investigation found no evidence that unauthorized persons accessed the data. The vendor secured the server, and Torrance Memorial offered 12 months of identity theft monitoring and restoration services to affected patients.
- Washington State AGas victim2020-03-06
Torrance Memorial Medical Center notified Washington AG of a breach affecting 1 WA resident (3,448 total). An outside radiology vendor's server was unsecured from 6/20/2019 to 12/13/2019. Patient images and PHI (name, DOB, MRN) were potentially accessible. No evidence of actual access. Vendor secured server; Torrance Memorial provided HIPAA training and credit monitoring.
- Montana State AGas victim2017-07-07
Torrance Memorial Medical Center experienced unauthorized access to email accounts of 5,797 Montana residents between April 16-19, 2017. The attacker used stolen credentials to access PHI and financial data. The incident was discovered on April 19, 2017. The company engaged forensic investigators, notified the FBI, and offered one year of credit monitoring.
- Montana State AGas victim2017-06-19
Torrance Memorial Medical Center reported a data breach to the Montana Attorney General. The breach was reported on 2017-06-19. The breach occurred from 4/18/2017 to 4/19/2017. 5 Montana residents were affected.
- Massachusetts State AGas victim2017-06-19
Torrance Memorial Medical Center reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-06-19. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-06-19
Torrance Memorial Medical Center reported an email security incident (phishing) occurring April 18-19, 2017, discovered April 20, 2017. Access was gained to two email accounts containing PHI, SSNs, names, DOBs, and addresses. One New Hampshire resident was notified. Investigation ongoing; no evidence of misuse. Credit monitoring offered.
- CALIFORNIAHHS OCRas victim2017-06-19
HHS OCR breach portal entry: Torrance Memorial Medical Center (CA) reported a Hacking/IT Incident involving Email on 2017-06-19, affecting 46,632 individuals per the portal count (the narrative text states 44,960 individuals plus 3,304 SSNs — discrepancy noted). Two workforce members responded to a phishing email, exposing PHI including names, addresses, DOBs, healthcare claims information, diagnoses, medications, other treatment information, and 3,304 SSNs. The CE notified HHS, affected individuals, and the media; remediation included expanded security training, enhanced authentication, and improved malicious-email controls. OCR's investigation closed with the CE improving PHI safeguards.
- California State AGas victim2017-06-19
Torrance Memorial Medical Center discovered an email security incident on April 20, 2017, involving unauthorized access to two staff members' email accounts containing work-related reports. Forensic evidence indicated the cyber attack occurred between April 18 and April 19, 2017. Affected data may include names, Social Security numbers, addresses, health insurance information, dates of birth, and treatment/diagnostic information. The organization engaged forensic investigators, notified regulators (CDPH, HHS, FBI), and offered one year of credit monitoring and identity theft restoration services via Experian.