Burrell Behavioral Health
ent_4207b3f4ecf7e76cdcbb380b
Disclosures
3
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
67,493
nationwide · HHS OCR MO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Burrell Behavioral Health
- Normalized
- burrell behavioral health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- burrellcenter.com
Disclosure history (3)newest first
- MISSOURIHHS OCRas victim2019-03-29
Burrell Behavioral Health reported to HHS on 2019-03-29 a Hacking/IT Incident affecting 67,493 individuals. Breached information located on Network Server. A business associate failed to secure a web portal containing PHI (names, addresses, DOB, SSN, clinical info). The portal lacked authentication and auditing. BBH removed access, investigated, notified individuals and OCR, offered identity monitoring, and terminated the BA relationship.
- Montana State AGas victim2016-09-06
Burrell Behavioral Health notified clients of a July 2016 incident where an employee's email account was compromised via phishing. Access potentially occurred July 6-7, 2016. PHI, SSNs, and PII were at risk. The company engaged forensic investigators, notified law enforcement and HHS, and offered one year of credit monitoring via Kroll.
- MISSOURIHHS OCRas victim2016-09-02
Burrell Behavioral Health reported to HHS on 2016-09-02 a Unauthorized Access/Disclosure affecting 7748 individuals. Breached information located on Email. An unauthorized individual accessed an employee's email account and sent PHI to the employee's ex-boyfriend.