HealthReach Community Health Centers
ent_8cb9498e4af5ce7c6caf3198
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
122,308
nationwide · HHS OCR ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HealthReach Community Health Centers
- Normalized
- healthreach community health centers— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- healthreach.org
Disclosure history (4)newest first
- Maine State AGas victim2021-09-09
HealthReach Community Health Centers reported a data breach involving the improper disposal of electronic hardware containing patient information, including names, government IDs, and financial account numbers. The incident affected 116,898 individuals, including 101,395 Maine residents. The breach occurred on April 7, 2021, was discovered on May 7, 2021, and notifications were sent on September 9, 2021. Affected individuals were offered 12 months of credit and dark web monitoring.
- Indiana State AGas victim2021-09-09
HealthReach Community Health Centers reported a data breach to the Indiana Attorney General. The breach occurred on 2021-04-07 and was reported on 2021-09-09. 63 Indiana residents were affected. 115,082 individuals affected in total.
- Montana State AGas victim2021-09-07
HealthReach Community Health Centers notified Montana residents of a data incident on September 7, 2021. On May 7, 2021, the organization learned that hard drives containing employee and customer PII (names, SSNs, DOBs, financial accounts) were improperly disposed of by a third-party vendor. No evidence of misuse was found. The company engaged counsel, monitored the situation, and provided 24 months of identity theft protection services.
- MAINEHHS OCRas victim2021-07-06
HealthReach Community Health Centers (ME) reported to HHS on 2021-07-06 an Improper Disposal breach affecting 122,308 individuals. The covered entity's business associate improperly disposed of hard drives containing PHI, including names, addresses, dates of birth, drivers' license and Social Security numbers, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, and the media, offered free credit monitoring, and the BA retrained staff on proper disposal procedures. Breached information located on Electronic Medical Record (hard drives).