Emory Healthcare
ent_1956ab55b6c876d33b0614b8
Disclosures
8
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
315,000
nationwide · HHS OCR GA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Emory Healthcare
- Normalized
- emory healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- emoryhealthcare.org
Disclosure history (8)newest first
- GEORGIAHHS OCRas victim2022-12-06
Emory Healthcare reported to HHS on 2022-12-06 an Unauthorized Access/Disclosure affecting 1891 individuals. Breached information located on Electronic Medical Record. An employee impermissibly accessed PHI (names, DOB, SSN) for unemployment benefits fraud. The employee was sanctioned and affected individuals received identity protection and credit monitoring.
- Massachusetts State AGas victim2022-12-06
Emory Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-12-06. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- GEORGIAHHS OCRas victim2017-12-15
Emory Healthcare, Inc. reported to HHS on 2017-12-15 a Unauthorized Access/Disclosure affecting 24,000 individuals. Breached information located on Email. A former employee placed files containing ePHI on a public server.
- Montana State AGas victim2017-12-15
Emory Healthcare notified patients that a former physician, now employed by the University of Arizona, placed patient medical records on a UA OneDrive account without authorization. The incident involved PHI including names, DOBs, and medical data from 2004-2014. No SSN or financial data was involved. The data was removed and expunged; no evidence of misuse was found.
- Montana State AGas victim2017-02-21
Emory Healthcare notified patients of a ransomware incident affecting the Waits & Delays appointment database. Unauthorized access occurred around January 1, 2017, when the database was deleted and a ransom demanded. Discovery was on January 3, 2017. Data included names, DOBs, contact info, and medical record numbers. No SSN or financial data was involved. Law enforcement was alerted.
- GEORGIAHHS OCRas victim2017-02-21
Emory Healthcare reported to HHS on 2017-02-21 a ransomware attack affecting 79,930 individuals. The breach involved protected health information, including names and dates of birth, located on a network server. In response, Emory Healthcare implemented additional security safeguards and received technical assistance from the Office for Civil Rights.
- California State AGas victim2012-05-16
Emory Healthcare, Inc. reported a data breach to the California Attorney General. The breach occurred on February 20, 2012. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- GEORGIAHHS OCRas victim2012-04-18
Emory Healthcare (GA) reported to HHS on 2012-04-18 that on February 20, 2012, ten unencrypted backup CDs containing ePHI were discovered missing. Clinical and demographic data for 315,000 surgical patients treated at three locations between September 1990 and April 2007 were affected. The CDs could only be read using decommissioned software. Breach notification was provided to HHS, affected individuals, and the media. Remediation included PHI inventory requirements and staff education. OCR obtained assurances of corrective action.