Bayhealth Hospital
ent_205c95d89076c59154be2f57
Disclosures
9
State AG · Leak Site · HHS OCR · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
17,481
as filed · HHS OCR DE
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Bayhealth Hospital
- Normalized
- bayhealth hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bayhealth.org
Disclosure history (9)newest first
- 🦬Montana State AGas reporting2025-02-03
Bayhealth Medical Center reported a data breach to the Montana Attorney General. The breach was reported on 2025-02-03. The breach occurred from 07/27/2024 to 07/31/2024. 61 Montana residents were affected.
- 💎Delaware State AGas reporting2025-02-03
Bayhealth Medical Center notified Delaware AG of a cybersecurity incident occurring July 27-31, 2024, involving unauthorized access to network systems. The breach compromised Protected Health Information (PHI) and personally identifiable information (PII), including names and government identifiers. The company engaged forensic specialists, notified federal law enforcement, and offered 12-24 months of credit monitoring and identity restoration services to affected individuals across multiple jurisdictions.
- ⛰️New Hampshire State AGas reporting2025-02-03
Bayhealth Medical Center experienced unauthorized access to its network between July 27 and July 31, 2024. The breach exposed Protected Health Information (PHI) and personal data of 185 New Hampshire residents. Bayhealth detected the suspicious activity on July 31, 2024, engaged forensic specialists, notified federal law enforcement, and provided credit monitoring services to affected individuals.
- 🐻California State AGas reporting2025-02-03
Bayhealth Medical Center experienced unauthorized access to its network between July 27 and July 31, 2024. The organization became aware of suspicious activity on July 31, 2024. The incident involved the acquisition of Protected Health Information (PHI) and other personal data. Forensic specialists were engaged, and federal law enforcement was notified. Credit monitoring services are being offered to affected individuals.
- 🍁Vermont State AGas reporting2025-02-03
Bayhealth Medical Center notified consumers of a cybersecurity incident where unauthorized access occurred between July 27 and July 31, 2024. The breach impacted names and Protected Health Information (PHI). The organization engaged forensic specialists, notified federal law enforcement, and is offering 12-24 months of credit monitoring. The incident status is contained.
- 💎Delaware State AGas reporting2025-02-03
Bayhealth Medical Center notified individuals of a data event involving unauthorized network access between July 27 and July 31, 2024. The incident involved the acquisition of names and Protected Health Information (PHI). Federal law enforcement was notified. Bayhealth offered 12-24 months of credit monitoring and identity restoration services. Approximately 159 Rhode Island residents were identified as potentially impacted.
- GLOBALLeak Siteas victim2024-08-07
Bayhealth Hospital Bayhealth is a technologically advanced not-for-profit healthcare system with nearly 4,000 employees and a medical staff of more than 450 physicians and 200 advanced practice clinicians.
- DELAWAREHHS OCRas reporting2022-06-30
Bayhealth Medical Center, Inc. (DE) reported to HHS OCR on 2022-06-30 a Hacking/IT Incident (ransomware) affecting 17,481 individuals. The attack was carried out against Bayhealth's business associate, whose network server was compromised. PHI exposed included names, addresses, dates of birth, Social Security numbers, financial information, and diagnoses. Bayhealth terminated its BA relationship, provided credit monitoring to affected individuals, and implemented additional technical safeguards and revised policies.
- DELAWAREHHS OCRas reporting2021-05-18
Bayhealth Medical Center, Inc. reported to HHS on 2021-05-18 a Hacking/IT Incident (ransomware attack) affecting 565 individuals. The covered entity's business associate was the direct victim. Breached ePHI resided on a network server and included names, dates of birth, and prescription information. The CE coordinated with its BA to notify HHS, affected individuals, the media, and posted substitute notice on its website.