Buddhist Tzu Chi Medical Foundation
ent_877537bf127bf24b557c9de5
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
18,968
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Buddhist Tzu Chi Medical Foundation
- Normalized
- buddhist tzu chi medical— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🌲Washington State AGas victim2021-10-20
Buddhist Tzu Chi Foundation, a non-profit/charity sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2021-07-15 and filed notice on 2021-10-20. 582 Washington residents were affected. 97 days elapsed between awareness and notification. 0 days to identify the breach.
- 🦬Montana State AGas victim2021-09-13
Buddhist Tzu Chi Medical Foundation reported a data breach to the Montana Attorney General. The breach was reported on 2021-09-13. The breach occurred on 7/15/2021. 2 Montana residents were affected.
- CALIFORNIAHHS OCRas victim2021-09-13
Buddhist Tzu Chi Medical Foundation (CA) reported to HHS OCR on 2021-09-13 a ransomware attack affecting 18,968 individuals. Breached information was located on a Network Server. PHI involved included names, addresses, dates of birth, and diagnoses. The CE notified HHS, affected individuals, and media, and provided substitute notice. In response, the CE strengthened administrative and technical safeguards and retrained staff. OCR provided technical assistance on HIPAA Privacy and Security Rule compliance.
- 🐻California State AGas victim2021-09-09
Buddhist Tzu Chi Medical Foundation discovered on July 15, 2021, that several computers were operating unusually and portions of its network were inaccessible. The organization took affected servers offline and initiated an investigation. It appears that encrypted servers may have contained protected health information (PHI), including names, dates of birth, diagnosis information, and dental x-rays. The investigation could not determine if the information was accessed or removed. The organization upgraded workstation security software and is migrating to a cloud-based dental x-ray platform.