Albert Einstein Healthcare Network
ent_6e80417aaba5a18fec8a3b5e
Disclosures
7
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
353,616
nationwide · HHS OCR PA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Albert Einstein Healthcare Network
- Normalized
- albert einstein healthcare network— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- California State AGas victim2021-01-25
Einstein Healthcare Network identified unauthorized access to employee email accounts between August 5 and August 17, 2020, after detecting suspicious activity on August 10, 2020. The incident potentially exposed patient PHI, including names, SSNs, and treatment details. Forensic investigation found no evidence of data viewing or misuse. The organization secured accounts, engaged forensics, and offered credit monitoring.
- Washington State AGas victim2021-01-25
Einstein Healthcare Network notified the Washington AG of a phishing incident affecting 1,197 residents. Unauthorized access to employee email accounts occurred Aug 5-17, 2020. PHI, SSNs, and DOBs were potentially exposed. Notifications mailed Jan-Feb 2021.
- Montana State AGas victim2021-01-21
Einstein Healthcare Network notified Montana residents of a security incident where unauthorized access to employee email accounts occurred between Aug 5-17, 2020. Suspicious activity was detected on Aug 10, 2020. Potential PHI and PII may have been accessed, though no evidence of misuse was found. Forensic investigators were engaged.
- Illinois State AGas victim2021-01-01
EINSTEIN HEALTHCARE NETWORK filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-030). The register records the breach as discovered on August 10, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- PENNSYLVANIAHHS OCRas victim2020-10-09
Einstein Healthcare Network reported to HHS on 2020-10-09 a Hacking/IT Incident affecting 353,616 individuals. Breached information located on Email. An employee was the victim of an email phishing attack that exposed ePHI including names, DOB, addresses, SSNs, and health insurance info. The entity notified HHS, individuals, and media, and strengthened security safeguards.
- PENNSYLVANIAHHS OCRas victim2016-04-01
Einstein Healthcare Network reported to HHS on 2016-04-01 a Unauthorized Access/Disclosure affecting 2939 individuals. Breached information located on Other. Between April 11, 2013 and March 21, 2017, a website form allowed PHI to be accessible via the internet. The CE worked with Google to remove indexed information and conducted a risk assessment and penetration test.
- PENNSYLVANIAHHS OCRas victim2010-11-30
Albert Einstein Healthcare Network (PA) reported to HHS OCR on 2010-11-30 a Theft incident affecting 613 individuals. The breached information was located on a Desktop Computer. No business associate was identified as present.