The Mount Kisco Surgery Center LLC
ent_410f810d5014be4bc30ffac2
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
22,139
as filed · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Mount Kisco Surgery Center LLC
- Normalized
- the mount kisco surgery center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🍁Vermont State AGas victim2024-06-26
The Ambulatory Surgery Center of Westchester (ASCW) notified 21,073 individuals of a data breach where an employee's email account was compromised via phishing between Oct 23 and Nov 3, 2023. The incident exposed names and protected health information. ASCW engaged forensic investigators, enhanced email security, and offered 12 months of identity protection services.
- 🏎️Indiana State AGas victim2024-06-26
The Mount Kisco Surgery Center LLC dba the Ambulatory Surgery Center of Westches reported a data breach to the Indiana Attorney General. The breach occurred on 2023-10-23 and was reported on 2024-06-26. 3 Indiana residents were affected. 21,073 individuals affected in total.
- ⛰️New Hampshire State AGas victim2024-06-26
The Mount Kisco Surgery Center LLC (dba ASCW) notified the NH AG of a data security incident. On Nov 3, 2023, unusual activity was discovered in an employee's email account. Unauthorized access occurred between Oct 23 and Nov 3, 2023. The incident involved phishing leading to credential compromise and email collection. Personal and PHI of 21,073 individuals were potentially affected, including 19 NH residents. ASCW engaged forensic investigators, secured the account, and offered identity protection services.
- NEW YORKHHS OCRas victim2024-06-25
The Mount Kisco Surgery Center LLC d/b/a The Ambulatory Surgery Center of Westchester (NY) reported a hacking/IT incident to HHS on 2024-06-25 affecting 22,139 individuals. Breached PHI was located in email and included names, SSNs, driver's license/state ID numbers, dates of birth, diagnoses, medications, claims, financial information, and health insurance/treatment information. The responsible employee was sanctioned and complimentary credit monitoring was provided.