Highlands-Cashiers Hospital
ent_7c1a54887021fb795ebe4ca2
Disclosures
3
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
26,115
nationwide · HHS OCR NC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Highlands-Cashiers Hospital
- Normalized
- highlands cashiers hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- NORTH CAROLINAHHS OCRas victim2014-12-11
Highlands Cashier Hospital reported to HHS on 2014-12-11 a breach involving unauthorized access or disclosure that affected 26,115 individuals. A business associate, Computer Programs and Systems, Inc., incorrectly configured the hospital's firewall, which exposed patient data on the internet. The exposed information, located on a network server, included patient names, addresses, dates of birth, treatment details, and, for 21,072 individuals, Social Security numbers. In response, the hospital implemented enhanced firewall safeguards, started monitoring web traffic, and began conducting external vulnerability scans.
- Massachusetts State AGas victim2014-11-28
Highlands-Cashiers Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-11-28. 26 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2014-11-26
Highlands-Cashiers Hospital notified the NH AG of a data exposure caused by third-party vendor TruBridge. Servers were inadvertently accessible via the Internet from May 2012 to Sept 2014. Data included patient PII, PHI, SSNs, and employee financial info. 5 NH residents affected. No evidence of actual access found. Credit monitoring offered.