Napa Valley Dentistry
ent_283cbb5d64e56b94aa824dd4
Disclosures
4
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,262
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Napa Valley Dentistry
- Normalized
- napa valley dentistry— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- CALIFORNIAHHS OCRas victim2016-10-05
Napa Valley Dentistry (NVD) reported to HHS OCR on 2016-10-05 a Theft affecting 4,262 individuals. An unencrypted server containing ePHI was stolen from NVD's offsite storage unit. Exposed data included names, dates of birth, Social Security numbers, addresses, and financial information. NVD responded with a risk analysis, risk management plan, policy updates, and additional HIPAA staff training. Breached information located on Other (server at offsite storage).
- Massachusetts State AGas victim2016-09-22
Napa Valley Dentistry reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-09-22. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2016-09-22
Napa Valley Dentistry reported the theft of a password-protected server from a secured storage unit on August 11, 2016. The server contained personal information including names, addresses, dates of birth, Social Security numbers, and dental insurance information for current and former patients. The organization notified the Napa Police Department and offered 12 months of complimentary credit monitoring and identity protection services through Kroll. No misuse of the information was known at the time of notification.
- Montana State AGas victim2016-09-22
Napa Valley Dentistry notified patients of a data breach involving the theft of a password-protected server from a secured storage unit. The server contained names, addresses, dates of birth, SSNs, and dental insurance info. Discovery was August 11, 2016. The firm offered 12 months of credit monitoring and terminated the storage contract.