Partners HealthCare System, Inc.
ent_4c007731158d2fe1eccfa562
Disclosures
6
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
3,321
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Partners HealthCare System, Inc.
- Normalized
- partners healthcare system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- MASSACHUSETTSHHS OCRas victim2018-02-05
Partners HealthCare System, Inc. reported to HHS on 2018-02-05 a Hacking/IT Incident affecting 2450 individuals. Breached information located on Desktop Computer, Network Server. The system was infected with malware. PHI involved included names, treatment information, Social Security numbers, and financial information. The CE updated technical safeguards and retrained its workforce.
- Massachusetts State AGas victim2018-02-05
Partners Healthcare Systems Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-02-05. 30 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-02-05
Partners HealthCare System, Inc. notified the NH Attorney General of a security incident involving malware detected on May 8, 2017. The malware may have resulted in unauthorized access to data on affected computers between May 8 and May 17, 2017. The incident potentially affected 2 New Hampshire residents, exposing personal information (name, SSN, financial account info) and protected health information. Partners engaged forensic consultants, contained the malware, and offered one year of credit monitoring.
- MASSACHUSETTSHHS OCRas victim2015-05-01
Partners HealthCare System, Inc. reported to HHS on 2015-05-01 a Hacking/IT Incident (phishing) affecting 3,321 individuals. A phishing email sent to 392 employees led to 50 employees providing unauthorized access to their email accounts, which were hosted on a Network Server. Breached PHI included names, addresses, dates of birth, Social Security numbers, diagnoses, medications, and other treatment information. The CE notified HHS, affected individuals, and the media, and subsequently implemented stronger passwords, two-factor authentication, and additional phishing awareness training. OCR obtained assurances of corrective action.
- Massachusetts State AGas victim2015-02-13
Partners HealthCare System, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-02-13. 2,559 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2015-02-12
Partners HealthCare System, Inc. notified the NH Attorney General on Feb 12, 2015, regarding a phishing incident discovered Nov 25, 2014. Workforce members provided credentials to attackers, leading to unauthorized access to PeopleSoft/HR systems. Affected data included names, SSNs, DOBs, and bank account numbers for employees and dependents. No specific count was provided. Remediation included forensic investigation and enhanced authentication.