Virginia Mason Medical Center
ent_8d5f190c531318d16243c54a
Disclosures
6
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
244,761
nationwide · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Virginia Mason Medical Center
- Normalized
- virginia mason medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- virginiamason.org
Disclosure history (6)newest first
- WASHINGTONHHS OCRas victim2022-05-31
Virginia Mason Medical Center (WA) reported to HHS OCR on 2022-05-31 a Hacking/IT Incident (cyber-attack) affecting 1,523 individuals. PHI on a Network Server was compromised, including names, addresses, birthdates, Social Security numbers, email addresses, and claims and treatment information. The CE notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards.
- WASHINGTONHHS OCRas victim2022-03-14
Virginia Mason Medical Center reported to HHS on 2022-03-14 a Hacking/IT Incident affecting 2733 individuals. Breached information located on Email. Employees were victims of an email phishing attack exposing PHI including names, SSNs, addresses, driver's license numbers, DOB, lab results, medications, and financial information. The entity notified HHS, individuals, and media, strengthened safeguards, and retrained staff.
- Washington State AGas victim2022-02-18
Virginia Mason Medical Center experienced a phishing attack between Dec 21, 2021 and Jan 3, 2022, compromising staff email accounts. The incident was discovered on Jan 18, 2022. Patient and employee data, including PHI, SSNs, and financial info, may have been accessed. 3,000 Washington residents were notified. VMMC reset credentials, blocked domains, and offered Kroll credit monitoring.
- Washington State AGas victim2020-09-08
Virginia Mason Medical Center notified the Washington AG of a third-party vendor breach involving Blackbaud. Unauthorized access occurred Feb 7–May 20, 2020. VMMC discovered the incident on July 16, 2020. The breach exposed patient names, contact info, DOBs, and visit details for 227,371 Washington residents. No SSNs or financial data were accessed. VMMC mailed notices on Sept 8, 2020.
- WASHINGTONHHS OCRas victim2020-09-08
Virginia Mason Medical Center (WA) reported to HHS on 2020-09-08 that its business associate experienced a ransomware attack affecting the ePHI of approximately 244,761 individuals. Breached information was located on a Network Server. Exposed data included names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice.
- Illinois State AGas victim2020-01-01
VIRGINIA MASON MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-342). The register records the breach as discovered on July 16, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.