Summit BHC West Virginia, LLC
ent_6faf534fd464238f7e452c69
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,804
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Summit BHC West Virginia, LLC
- Normalized
- summit bhc west virginia— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- New Hampshire State AGas victim2022-04-05
Summit BHC West Virginia, LLC d/b/a Highland Hospital experienced a security incident on October 26, 2021, when an unauthorized party accessed an employee's ADP portal and altered payroll information. This triggered an alert, leading to the discovery that an unauthorized third party had logged into five employee email accounts. The incident potentially exposed PHI, PII, and financial information of patients and employees, including one New Hampshire resident. The actor attempted unsuccessful payment fraud. Highland contained the incident, reset passwords, implemented MFA, and offered credit monitoring.
- Massachusetts State AGas victim2022-04-01
Summit BHC West Virginia, LLC d/b/a Highland Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-04-01. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2022-03-31
Summit BHC West Virginia, LLC dba Highland Hospital reported a data breach to the Indiana Attorney General. 3 Indiana residents were affected. 6,804 individuals affected in total.
- WEST VIRGINIAHHS OCRas victim2022-02-10
Summit BHC West Virginia, LLC d/b/a Highland Hospital reported to HHS on 2022-02-10 a Hacking/IT Incident (email phishing attack) affecting 6,804 individuals. Multiple employees were victims of a phishing attack. PHI exposed included names, addresses, email addresses, dates of birth, Social Security numbers, health insurance information, claims and financial information, and other treatment information. Breached information located in Email. The CE notified HHS, individuals, and the media, and implemented additional technical safeguards and revised policies.