Bayhealth Medical Center
ent_205c95d89076c59154be2f57
Disclosures
14
State AG · HHS OCR · Leak Site · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
497,047
nationwide · HHS OCR DE
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Bayhealth Medical Center
- Normalized
- bayhealth medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bayhealth.org
Disclosure history (14)newest first
- Montana State AGas victim2025-02-03
Bayhealth Medical Center notified Montana and Rhode Island residents of unauthorized network access occurring July 27-31, 2024. Suspicious activity was detected July 31, 2024. PHI and PII were accessed. The company engaged forensic specialists, notified law enforcement, and offered credit monitoring.
- Maine State AGas victim2025-02-03
Bayhealth Medical Center reported an external system breach (hacking) occurring between July 27 and July 31, 2024. The incident compromised PHI, SSNs, driver's licenses, and names. 257 Maine residents were notified on February 3, 2025. The organization engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring.
- Nebraska State AGas victim2025-02-03
Bayhealth Medical Center notified Nebraska AG of a data event occurring between July 27-31, 2024, discovered July 31, 2024. Unauthorized access resulted in the acquisition of names, SSNs, driver's license numbers, and PHI. 66 Nebraska residents were notified starting October 4, 2024. Response included forensic investigation, law enforcement notification, and 12 months of credit monitoring.
- New Hampshire State AGas victim2025-02-03
Bayhealth Medical Center experienced unauthorized access to its network between July 27 and July 31, 2024. The breach exposed Protected Health Information (PHI) and personal data of 185 New Hampshire residents. Bayhealth detected the suspicious activity on July 31, 2024, engaged forensic specialists, notified federal law enforcement, and provided credit monitoring services to affected individuals.
- California State AGas victim2025-02-03
Bayhealth Medical Center experienced unauthorized access to its network between July 27 and July 31, 2024. The organization became aware of suspicious activity on July 31, 2024. The incident involved the acquisition of Protected Health Information (PHI) and other personal data. Forensic specialists were engaged, and federal law enforcement was notified. Credit monitoring services are being offered to affected individuals.
- Vermont State AGas victim2025-02-03
Bayhealth Medical Center notified consumers of a cybersecurity incident where unauthorized access occurred between July 27 and July 31, 2024. The breach impacted names and Protected Health Information (PHI). The organization engaged forensic specialists, notified federal law enforcement, and is offering 12-24 months of credit monitoring. The incident status is contained.
- Massachusetts State AGas victim2025-02-03
Bayhealth Medical Center reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-02-03. 894 Massachusetts residents were affected.
- Delaware State AGas victim2025-02-03
Bayhealth Medical Center notified individuals of a data event involving unauthorized network access between July 27 and July 31, 2024. The incident involved the acquisition of names and Protected Health Information (PHI). Federal law enforcement was notified. Bayhealth offered 12-24 months of credit monitoring and identity restoration services. Approximately 159 Rhode Island residents were identified as potentially impacted.
- Illinois State AGas victim2025-02-01
BAYHEALTH MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General in February 2025 (case 25-02-008). The register records the breach as discovered on July 27, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- DELAWAREHHS OCRas victim2024-10-04
Bayhealth Medical Center reported to HHS on 2024-10-04 a Hacking/IT Incident affecting 497047 individuals. Breached information located on Network Server. PHI included SSNs, addresses, DOBs, diagnoses, and medications.
- GLOBALLeak Siteas victim2024-08-07
Bayhealth Hospital Bayhealth is a technologically advanced not-for-profit healthcare system with nearly 4,000 employees and a medical staff of more than 450 physicians and 200 advanced practice clinicians.
- DELAWAREHHS OCRas victim2022-06-30
Bayhealth Medical Center, Inc. (DE) reported to HHS OCR on 2022-06-30 a Hacking/IT Incident (ransomware) affecting 17,481 individuals. The attack was carried out against Bayhealth's business associate, whose network server was compromised. PHI exposed included names, addresses, dates of birth, Social Security numbers, financial information, and diagnoses. Bayhealth terminated its BA relationship, provided credit monitoring to affected individuals, and implemented additional technical safeguards and revised policies.
- DELAWAREHHS OCRas victim2021-05-18
Bayhealth Medical Center, Inc. reported to HHS on 2021-05-18 a Hacking/IT Incident (ransomware attack) affecting 565 individuals. The covered entity's business associate was the direct victim. Breached ePHI resided on a network server and included names, dates of birth, and prescription information. The CE coordinated with its BA to notify HHS, affected individuals, the media, and posted substitute notice on its website.
- DELAWAREHHS OCRas victim2020-11-20
Bayhealth Medical Center, Inc. reported to HHS on 2020-11-20 a Hacking/IT Incident affecting 78006 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting PHI including names, addresses, gender, DOB, and treatment info.