Buddhist Tzu Chi Medical Foundation
ent_877537bf127bf24b557c9de5
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
18,968
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Buddhist Tzu Chi Medical Foundation
- Normalized
- buddhist tzu chi medical— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Washington State AGas victim2021-10-20
Buddhist Tzu Chi Foundation reported a ransomware incident on July 15, 2021, affecting 582 Washington residents. Encrypted servers may have contained PII including names, addresses, emails, and SSNs. Notices were sent October 12, 2021, offering credit monitoring.
- Montana State AGas victim2021-09-13
Buddhist Tzu Chi Medical Foundation notified Montana residents of a July 15, 2021 incident where unusual computer activity and inaccessible network portions were discovered. Encrypted servers likely contained PHI including names, DOBs, diagnoses, and dental x-rays. Two Montana residents were notified on September 13, 2021. Systems were taken offline and security software upgraded.
- CALIFORNIAHHS OCRas victim2021-09-13
Buddhist Tzu Chi Medical Foundation (CA) reported to HHS OCR on 2021-09-13 a ransomware attack affecting 18,968 individuals. Breached information was located on a Network Server. PHI involved included names, addresses, dates of birth, and diagnoses. The CE notified HHS, affected individuals, and media, and provided substitute notice. In response, the CE strengthened administrative and technical safeguards and retrained staff. OCR provided technical assistance on HIPAA Privacy and Security Rule compliance.
- California State AGas victim2021-09-09
Buddhist Tzu Chi Medical Foundation discovered on July 15, 2021, that several computers were operating unusually and portions of its network were inaccessible. The organization took affected servers offline and initiated an investigation. It appears that encrypted servers may have contained protected health information (PHI), including names, dates of birth, diagnosis information, and dental x-rays. The investigation could not determine if the information was accessed or removed. The organization upgraded workstation security software and is migrating to a cloud-based dental x-ray platform.