Cancer Treatment Centers of America
ent_2a1e9b7c147710241a826ecf
Disclosures
23
State AG · HHS OCR · 10 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
41,948
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cancer Treatment Centers of America
- Normalized
- cancer treatment centers of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (23)newest first
- Montana State AGas victim2021-03-19
Cancer Treatment Centers of America notified Montana AG of a security incident involving unauthorized access to an employee email account between Jan 12-18, 2021. Suspicious activity was detected on Jan 18. Affected data included names, medical record numbers, health insurance info, and limited medical information. No SSN or financial data involved.
- Washington State AGas victim2021-03-19
Cancer Treatment Centers of America at Midwestern Regional Medical Center notified Washington AG of a phishing incident affecting one employee's email account. Unauthorized access occurred Jan 12-18, 2021. Data included names, medical record numbers, health insurance info, and account numbers for 579 WA residents. No SSNs or financial info involved. Notices sent March 19, 2021.
- Illinois State AGas victim2021-01-01
CANCER TREATMENT CENTERS OF AMERICA filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-142). The register records the breach as discovered on January 18, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Oregon State AGas victim2019-09-27
Cancer Treatment Centers of America at Southeastern Regional Medical Center reported a data breach to the Oregon Attorney General. The breach was reported on 2019-09-27. The breach occurred during 7/22/2019 - 7/30/2019. The breach was discovered on 7/29/2019. 3,290 individuals were affected. Notice was sent on 9/27/2019.
- GEORGIAHHS OCRas victim2019-09-27
Cancer Treatment Centers of America (CTCA) at Southeastern Regional Medical Center reported to HHS on 2019-09-27 a Hacking/IT Incident affecting 3290 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing ePHI including names, SSNs, DOB, financial and clinical data. CE implemented safeguards and retrained staff.
- Oregon State AGas victim2019-07-15
Cancer Treatment Centers of America at Eastern Regional Medical Center reported a data breach to the Oregon Attorney General. The breach was reported on 2019-07-15. The breach occurred during 5/4/2019 - 5/15/2019. The breach was discovered on 6/6/2019. 3,904 individuals were affected. Notice was sent on 7/12/2019.
- Oregon State AGas victim2019-07-15
Cancer Treatment Centers of America at Southeastern Regional Medical Center reported a data breach to the Oregon Attorney General. The breach was reported on 2019-07-15. The breach occurred during 4/17/2019 - 5/15/2019. The breach was discovered on 5/15/2019. 4,559 individuals were affected. Notice was sent on 7/12/2019.
- PENNSYLVANIAHHS OCRas victim2019-07-12
Cancer Treatment Centers of America (CTCA) at Eastern Regional Medical Center reported to HHS on 2019-07-12 a Hacking/IT Incident affecting 3904 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing ePHI including names, SSNs, DOB, financial and clinical data.
- Montana State AGas victim2019-07-12
Cancer Treatment Centers of America (CTCA) notified Montana AG of a phishing incident affecting a user's email account. Unauthorized access occurred between April 17 and May 15, 2019. Affected data included names, phone numbers, addresses, DOBs, medical record numbers, and health insurance info. CTCA engaged forensic investigators and reset credentials.
- Montana State AGas victim2019-07-12
Cancer Treatment Centers of America (CTCA) notified Montana residents of a security incident involving unauthorized access to a user's email account. Suspicious activity occurred between May 4 and May 15, 2019, and was detected on June 6, 2019. Affected data included names, phone numbers, addresses, DOB, medical record numbers, and health information. CTCA engaged forensic investigators and is evaluating security enhancements.
- GEORGIAHHS OCRas victim2019-07-12
Cancer Treatment Centers of America (CTCA) at Southeastern Regional Medical Center (GA) reported to HHS OCR on 2019-07-12 a Hacking/IT Incident affecting 4,559 individuals. Several employees were victims of an email phishing scheme, exposing ePHI including names, phone numbers, addresses, dates of birth, health insurance information, and clinical information stored in email. The CE implemented additional technical safeguards, retrained staff on phishing recognition, and OCR obtained assurances of corrective action.
- Oregon State AGas victim2019-05-21
Cancer Treatment Centers of America reported a data breach to the Oregon Attorney General. The breach was reported on 2019-05-21. The breach occurred during 3/10/2019 - 3/10/2019. The breach was discovered on 3/11/2019. 16,819 individuals were affected. Notice was sent on 5/10/2019.
- Massachusetts State AGas victim2019-05-13
Cancer Treatment Centers of America reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-05-13. 37 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2019-05-12
CTCA at Southeastern Regional Medical Center notified NH AG of a phishing incident on March 11, 2019. An employee's email was accessed by an unauthorized user between March 10-11, 2019, after providing credentials via a fraudulent email. 20 NH residents affected; data included names, government IDs, medical info, PHI. No SSNs or financial data involved. Forensics retained; passwords reset.
- Montana State AGas victim2019-05-10
CTCA Southeastern Regional Medical Center notified Montana residents of a phishing attack on March 11, 2019, which compromised an employee's email account. Affected data included names, medical record numbers, health insurance info, and government IDs. No SSN or financial data was involved. CTCA engaged forensic investigators and reset credentials.
- GEORGIAHHS OCRas victim2019-05-10
Cancer Treatment Centers of America (CTCA) at Southeastern Regional Medical Center (GA) reported to HHS OCR on 2019-05-10 a Hacking/IT Incident affecting 16,819 individuals. Several employees were victims of an email phishing scheme that compromised ePHI including names, Social Security numbers, addresses, dates of birth, financial information, health insurance information, and clinical information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional technical safeguards and employee retraining. OCR obtained corrective action assurances.
- Illinois State AGas victim2019-01-01
CANCER TREATMENT CENTERS OF AMERICA AT SOUTHEASTERN MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-396). The register records the breach as discovered on July 22, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2019-01-01
CANCER TREATMENT CENTERS OF AMERICA AT EASTERN REGIONAL MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-259). The register records the breach as discovered on May 4, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2019-01-01
CANCER TREATMENT CENTERS OF AMERICA AT EASTERN REGIONAL MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-260). The register records the breach as discovered on April 17, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Oregon State AGas victim2018-11-30
Cancer Treatment Centers of America reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-30. The breach occurred during 5/2/2018 - 5/2/2018. The breach was discovered on 9/26/2018. Notice was sent on 11/26/2018.
- California State AGas victim2018-11-27
Cancer Treatment Centers of America at Western Regional Medical Center reported a data breach to the California Attorney General. The filing indicates the breach occurred on May 2, 2018. No further details regarding the nature of the breach, data types affected, or number of individuals impacted are provided in this summary record.
- Montana State AGas victim2018-11-26
CTCA notified Montana residents of a phishing attack on an employee's email account. Unauthorized access occurred on May 2, 2018. Data potentially exposed included names, addresses, DOB, and PHI. No SSN or financial data involved. Forensics retained; password reset and staff training implemented.
- ARIZONAHHS OCRas victim2018-11-26
Cancer Treatment Centers of America (CTCA) at Western Regional Medical Center reported to HHS on 2018-11-26 a Hacking/IT Incident affecting 41,948 individuals. Breached information located on Email. An employee was the victim of an email phishing attack exposing PHI including names, addresses, SSNs, diagnoses, and treatment info.