Highline Medical Center
ent_5b722257f2a160b6acf2dadc
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
18,399
nationwide · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Highline Medical Center
- Normalized
- highline medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Massachusetts State AGas victim2016-09-01
CHI Franciscan Healthcare Highline Medical Center reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-09-01. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- WASHINGTONHHS OCRas victim2016-09-01
CHI Franciscan Health Highline Medical Center (WA) reported to HHS OCR on 2016-09-01 an Unauthorized Access/Disclosure affecting 18,399 individuals. A business associate inadvertently left files containing patient ePHI publicly accessible via the internet from approximately mid-April 2016 to June 13, 2016. Breached information located on Network Server included patient names, dates of service, health insurance information, and Social Security numbers. Following the breach, the CE terminated the BA relationship and the BA deleted all patient files from its systems.
- Washington State AGas victim2016-08-31
Highline Medical Center notified Washington AG that vendor R-C Healthcare Management inadvertently left patient files accessible online from April 21 to June 13, 2016. Highline discovered the breach on July 22, 2016. Data included names, SSNs, and insurance info for 12,724 Washington residents. Highline offered credit monitoring and established a call center.
- Montana State AGas reporting2016-08-31
M Holdings Securities, Inc. notified Montana residents that a company computer containing personal information (names, SSNs, driver's licenses, financial account numbers) was stolen from an employee's car. The device was password-protected. The company retained forensic investigators, offered 12 months of identity protection, and notified law enforcement.