Virginia Department of Medical Assistance Services
ent_1f730f774857fd20a444a733
Disclosures
4
HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,229,333
nationwide · HHS OCR VA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Virginia Department of Medical Assistance Services
- Normalized
- virginia department of medical assistance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- VAHHS OCRas victim2023-09-18
Virginia Department of Medical Assistance Services reported to HHS on 2023-09-18 a Hacking/IT Incident affecting 1,229,333 individuals. The breach involved a business associate compromising PHI (names, birthdates, SSN, driver's license, claims, treatment info) located on a Network Server. The CE and BA implemented additional administrative and technical safeguards.
- VAHHS OCRas victim2023-08-09
Virginia Department of Medical Assistance Services reported to HHS on 2023-08-09 a Hacking/IT Incident affecting 423,824 individuals. The breach involved a cyber-attack on business associate Brooklyn Premier Orthopedics, exposing PHI (names, addresses, DOB, SSN, diagnoses, medications) on a network server. The CE provided credit monitoring and implemented additional safeguards.
- VAHHS OCRas victim2020-01-31
Virginia Department of Medical Assistance Services reported to HHS on 2020-01-31 a Hacking/IT Incident affecting 6120 individuals. Breached information located on Electronic Medical Record, Network Server. Employees were victims of an email phishing scheme affecting ePHI including names, Medicaid IDs, and treatment info. CE implemented additional administrative and technical safeguards.
- FEDERALHHS OCRas victim2015-03-12
Virginia Department of Medical Assistance Services (VA-DMAS) reported a breach to HHS on March 12, 2015, affecting 697,586 individuals. The breach was a Hacking/IT Incident that occurred at its business associate, Healthkeepers, due to a series of cyberattacks on its parent company, Anthem, Inc. The exposed information included names, Social Security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information. OCR opened a separate review of Anthem, resulting in a monetary settlement and a corrective action plan.