Children's National Medical Center
ent_1f4328118bd5a8288318eceb
Disclosures
3
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
18,000
as filed · HHS OCR DC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Children's National Medical Center
- Normalized
- children s national medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- childrensnational.org
Disclosure history (3)newest first
- DCHHS OCRas victim2018-03-30
Children’s National Medical Center reported to HHS on 2018-03-30 a Theft affecting 722 individuals. Breached information located on Laptop. A laptop containing patient PHI (names, DOB, diagnoses, lab results, medications) was stolen from an employee's vehicle. The entity notified HHS, individuals, media, and law enforcement, and implemented additional safeguards.
- DCHHS OCRas victim2016-04-25
Children's National Medical Center (DC) reported to HHS on 2016-04-25 an Unauthorized Access/Disclosure affecting 4,107 individuals. A former business associate, Ascend Health System, misconfigured an FTP site, potentially exposing transcription documents via the internet. Breached PHI included children's names, dates of birth, medications, and physicians' names. The breach was discovered in December 2015; the CE had ceased business with the BA on June 23, 2014. Notification was provided to HHS, affected individuals, and the media.
- DCHHS OCRas victim2015-02-24
Children's National Medical Center (DC) reported to HHS on 2015-02-24 a Hacking/IT Incident affecting 18,000 individuals (described as over 20,000 in the narrative). Employees responded to phishing emails, enabling unauthorized access via compromised credentials. Breached information — located in Email systems — included demographic, clinical, and health insurance data, and a limited number of Social Security numbers. Exfiltration software was deployed by the attacker. The CE remediated accounts, removed exfil tools, enhanced firewall/email controls, retrained staff, and offered 12 months of free identity monitoring for SSN-affected individuals. OCR obtained assurances of corrective action completion.